VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 445 of 668
  • CVE-2020-8124MedFeb 4, 2020
    risk 0.28cvss 5.3epss 0.02

    Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

  • CVE-2020-8122MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

  • CVE-2018-1002104MedJan 14, 2020
    risk 0.28cvss 5.3epss 0.01

    Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.

  • CVE-2019-18995MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.02

    The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.

  • CVE-2019-8670MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.

  • CVE-2019-15971MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file…

  • CVE-2019-5864MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.00

    Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

  • CVE-2019-13675MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.

  • CVE-2013-1811MedNov 7, 2019
    risk 0.28cvss 4.3epss 0.01

    An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

  • CVE-2010-3667MedNov 4, 2019
    risk 0.28cvss 5.3epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

  • CVE-2013-1930MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

  • CVE-2019-6654MedSep 25, 2019
    risk 0.28cvss 4.3epss 0.00

    On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force…

  • CVE-2019-1204MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a…

  • CVE-2019-7899MedAug 2, 2019
    risk 0.28cvss 5.3epss 0.01

    Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

  • CVE-2019-7898MedAug 2, 2019
    risk 0.28cvss 5.3epss 0.01

    Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.

  • CVE-2017-18461MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).

  • CVE-2017-18440MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).

  • CVE-2016-10765MedJul 29, 2019
    risk 0.28cvss 5.3epss 0.01

    edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

  • CVE-2019-5839MedJun 27, 2019
    risk 0.28cvss 4.3epss 0.01

    Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.

  • CVE-2019-0094MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.00

    Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.