CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 466 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-21639 | Med | 0.21 | 4.3 | 0.03 | Apr 7, 2021 | Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type. | ||
| CVE-2021-21606 | Med | 0.21 | 4.3 | 0.01 | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path. | ||
| CVE-2020-0368 | Low | 0.21 | 3.3 | 0.00 | Dec 15, 2020 | In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2019-8857 | Low | 0.21 | 3.3 | 0.00 | Oct 27, 2020 | The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel. | ||
| CVE-2020-15731 | Low | 0.21 | 3.2 | 0.01 | Sep 30, 2020 | An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions… | ||
| CVE-2020-15192 | Med | 0.21 | 4.3 | 0.01 | Sep 25, 2020 | In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each… | ||
| CVE-2019-10806 | Med | 0.21 | 4.3 | 0.01 | Mar 9, 2020 | vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype. | ||
| CVE-2013-0342 | Med | 0.21 | 4.3 | 0.02 | Dec 9, 2019 | The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294. | ||
| CVE-2009-3614 | Low | 0.21 | 3.3 | 0.00 | Nov 9, 2019 | liboping 1.3.2 allows users reading arbitrary files upon the local system. | ||
| CVE-2017-18458 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219). | ||
| CVE-2018-20873 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | ||
| CVE-2018-4446 | Low | 0.21 | 3.3 | 0.01 | Apr 3, 2019 | This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1. | ||
| CVE-2018-4322 | Low | 0.21 | 3.3 | 0.00 | Apr 3, 2019 | This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12. | ||
| CVE-2018-12222 | Low | 0.21 | 3.3 | 0.00 | Mar 14, 2019 | Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables… | ||
| CVE-2018-10858 | Med | 0.21 | 4.3 | 0.04 | Aug 22, 2018 | A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable. | ||
| CVE-2018-1999037 | Med | 0.21 | 4.3 | 0.01 | Aug 1, 2018 | A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource. | ||
| CVE-2016-8612 | Med | 0.21 | 4.3 | 0.04 | Mar 9, 2018 | Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process. | ||
| CVE-2017-8164 | Low | 0.21 | 3.3 | 0.01 | Mar 5, 2018 | Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145;… | ||
| CVE-2017-17292 | Low | 0.21 | 3.3 | 0.00 | Feb 15, 2018 | Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01,… | ||
| CVE-2018-5278 | Low | 0.21 | 3.3 | 0.00 | Jan 8, 2018 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able… |
- risk 0.21cvss 4.3epss 0.03
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type.
- risk 0.21cvss 4.3epss 0.01
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
- risk 0.21cvss 3.3epss 0.00
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.21cvss 3.3epss 0.00
The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.
- risk 0.21cvss 3.2epss 0.01
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions…
- risk 0.21cvss 4.3epss 0.01
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each…
- risk 0.21cvss 4.3epss 0.01
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
- risk 0.21cvss 4.3epss 0.02
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
- risk 0.21cvss 3.3epss 0.00
liboping 1.3.2 allows users reading arbitrary files upon the local system.
- risk 0.21cvss 3.3epss 0.00
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
- risk 0.21cvss 3.3epss 0.00
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
- risk 0.21cvss 3.3epss 0.01
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.
- risk 0.21cvss 3.3epss 0.00
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.
- risk 0.21cvss 3.3epss 0.00
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables…
- risk 0.21cvss 4.3epss 0.04
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
- risk 0.21cvss 4.3epss 0.01
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
- risk 0.21cvss 4.3epss 0.04
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
- risk 0.21cvss 3.3epss 0.01
Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145;…
- risk 0.21cvss 3.3epss 0.00
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01,…
- risk 0.21cvss 3.3epss 0.00
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able…