CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 79 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-8723 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2019 | Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege. | ||
| CVE-2019-8722 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2019 | Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege. | ||
| CVE-2019-8721 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2019 | Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege. | ||
| CVE-2019-8503 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2019 | A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website. | ||
| CVE-2016-1000104 | Hig | 0.57 | 8.8 | 0.02 | Dec 3, 2019 | A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. | ||
| CVE-2011-4120 | Cri | 0.57 | 9.8 | 0.02 | Nov 26, 2019 | Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and… | ||
| CVE-2019-15288 | Hig | 0.57 | 8.8 | 0.02 | Nov 26, 2019 | A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due… | ||
| CVE-2019-19249 | Cri | 0.57 | 9.8 | 0.01 | Nov 25, 2019 | Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations. | ||
| CVE-2019-5858 | Hig | 0.57 | 8.8 | 0.01 | Nov 25, 2019 | Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page. | ||
| CVE-2019-5856 | Hig | 0.57 | 8.8 | 0.01 | Nov 25, 2019 | Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. | ||
| CVE-2019-13692 | Hig | 0.57 | 8.8 | 0.01 | Nov 25, 2019 | Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page. | ||
| CVE-2012-5582 | Cri | 0.57 | 9.8 | 0.02 | Nov 25, 2019 | opendnssec misuses libcurl API | ||
| CVE-2013-2093 | Cri | 0.57 | 9.8 | 0.05 | Nov 20, 2019 | Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands. | ||
| CVE-2011-1028 | Cri | 0.57 | 9.8 | 0.02 | Nov 20, 2019 | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | ||
| CVE-2012-4438 | Hig | 0.57 | 8.8 | 0.02 | Nov 18, 2019 | Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code. | ||
| CVE-2019-3426 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2019 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations. | ||
| CVE-2010-2447 | Cri | 0.57 | 9.8 | 0.02 | Nov 7, 2019 | gitolite before 1.4.1 does not filter src/ or hooks/ from path names. | ||
| CVE-2002-2444 | Cri | 0.57 | 9.8 | 0.02 | Oct 28, 2019 | Snoopy before 2.0.0 has a security hole in exec cURL | ||
| CVE-2019-0070 | Hig | 0.57 | 8.8 | 0.00 | Oct 9, 2019 | An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This leads to the… | ||
| CVE-2019-17346 | Hig | 0.57 | 8.8 | 0.00 | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes. |
- risk 0.57cvss 8.8epss 0.02
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
- risk 0.57cvss 8.8epss 0.02
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
- risk 0.57cvss 8.8epss 0.02
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
- risk 0.57cvss 8.8epss 0.02
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website.
- risk 0.57cvss 8.8epss 0.02
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
- risk 0.57cvss 9.8epss 0.02
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and…
- risk 0.57cvss 8.8epss 0.02
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due…
- risk 0.57cvss 9.8epss 0.01
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
- risk 0.57cvss 8.8epss 0.01
Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
- risk 0.57cvss 9.8epss 0.02
opendnssec misuses libcurl API
- risk 0.57cvss 9.8epss 0.05
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
- risk 0.57cvss 9.8epss 0.02
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
- risk 0.57cvss 8.8epss 0.02
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could exploit this vulnerability for unauthorized operations.
- risk 0.57cvss 9.8epss 0.02
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
- risk 0.57cvss 9.8epss 0.02
Snoopy before 2.0.0 has a security hole in exec cURL
- risk 0.57cvss 8.8epss 0.00
An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This leads to the…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.