VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 431 of 668
  • CVE-2019-11102MedDec 18, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local…

  • CVE-2019-11101MedDec 18, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2019-0168MedDec 18, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2019-0165MedDec 18, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2013-0180MedNov 1, 2019
    risk 0.29cvss 5.5epss 0.00

    Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

  • CVE-2013-0178MedNov 1, 2019
    risk 0.29cvss 5.5epss 0.00

    Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

  • CVE-2019-15273MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.00

    Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permission enforcement. An attacker could exploit these…

  • CVE-2019-9453MedSep 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-1960MedAug 8, 2019
    risk 0.29cvss 4.4epss 0.00

    Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details…

  • CVE-2019-1959MedAug 8, 2019
    risk 0.29cvss 4.4epss 0.00

    Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details…

  • CVE-2017-18465MedAug 5, 2019
    risk 0.29cvss 4.4epss 0.00

    cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).

  • CVE-2019-11114MedMay 17, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2019-1588MedMar 6, 2019
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation…

  • CVE-2018-19640MedMar 5, 2019
    risk 0.29cvss 4.4epss 0.00

    If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.

  • CVE-2018-5498MedFeb 1, 2019
    risk 0.29cvss 4.4epss 0.01

    Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerability will allow a remote authenticated attacker to cause a…

  • CVE-2018-12167MedJan 10, 2019
    risk 0.29cvss 4.4epss 0.00

    Firmware update routine in bootloader for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.

  • CVE-2018-12166MedJan 10, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient write protection in firmware for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.

  • CVE-2018-5515MedMay 2, 2018
    risk 0.29cvss 4.4epss 0.03

    On F5 BIG-IP 13.0.0-13.1.0.5, using RADIUS authentication responses from a RADIUS server with IPv6 addresses may cause TMM to crash, leading to a failover event.

  • CVE-2018-1099MedApr 3, 2018
    risk 0.29cvss 5.5epss 0.01

    DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

  • CVE-2018-0211MedMar 8, 2018
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be manually rebooted to recover. The vulnerability is due to lack of proper input…