VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 465 of 668
  • CVE-2023-21431LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.

  • CVE-2023-22734MedJan 17, 2023
    risk 0.21cvss 4.3epss 0.01

    Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their…

  • CVE-2022-3171MedOct 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be…

  • CVE-2022-39236MedSep 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note…

  • CVE-2022-36853LowSep 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

  • CVE-2022-20338LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no additional execution privileges…

  • CVE-2022-20241LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-31036MedJun 27, 2022
    risk 0.21cvss 4.3epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive YAML files from Argo CD's repo-server. A…

  • CVE-2022-25839MedMar 11, 2022
    risk 0.21cvss 4.3epss 0.01

    The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and…

  • CVE-2022-0174MedJan 10, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.

  • CVE-2021-4117MedDec 15, 2021
    risk 0.21cvss 4.3epss 0.01

    yetiforcecrm is vulnerable to Business Logic Errors

  • CVE-2021-4111MedDec 15, 2021
    risk 0.21cvss 4.3epss 0.01

    yetiforcecrm is vulnerable to Business Logic Errors

  • CVE-2021-42070LowDec 14, 2021
    risk 0.21cvss 3.3epss 0.01

    When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application

  • CVE-2021-42068LowDec 14, 2021
    risk 0.21cvss 3.3epss 0.01

    When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2021-22457LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write.

  • CVE-2021-42009MedOct 12, 2021
    risk 0.21cvss 4.3epss 0.03

    An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitrary body to an…

  • CVE-2021-25465LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.

  • CVE-2021-30671LowSep 8, 2021
    risk 0.21cvss 3.3epss 0.01

    A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to send unauthorized Apple events to Finder.

  • CVE-2021-3655LowAug 5, 2021
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.

  • CVE-2021-29433MedApr 15, 2021
    risk 0.21cvss 4.3epss 0.01

    Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for…