VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 409 of 668
  • CVE-2024-38303MedAug 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2024-27241MedJul 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-34473MedMay 4, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.

  • CVE-2024-32645MedApr 25, 2024
    risk 0.34cvss 5.3epss 0.00

    Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable…

  • CVE-2024-21590MedApr 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS Evolved allows an unauthenticated attacker within the MPLS administrative domain to send specifically crafted packets to the Routing Engine (RE) to cause a…

  • CVE-2023-45177MedMar 20, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM X-Force ID: 268066.

  • CVE-2021-33146MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2023-52368MedFeb 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-4553MedJan 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects AppBuilder: from 21.2 before 23.2.

  • CVE-2023-46763MedNov 8, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.

  • CVE-2023-3770MedOct 2, 2023
    risk 0.34cvss 5.3epss 0.00

     Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol (1925/UDP) to obtain device-specific information without the need for authentication.

  • CVE-2023-31011MedSep 20, 2023
    risk 0.34cvss 5.2epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

  • CVE-2023-39265LowSep 6, 2023
    risk 0.34cvss 3.8epss 0.84

    Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if…

  • CVE-2023-3704MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.01

    The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable…

  • CVE-2023-36674MedAug 20, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.

  • CVE-2023-20232MedAug 16, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP…

  • CVE-2023-30559MedJul 13, 2023
    risk 0.34cvss 5.2epss 0.00

    The firmware update package for the wireless card is not properly signed and can be modified.

  • CVE-2023-3456MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-30663MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

  • CVE-2021-36402MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.