CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 80 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17042 | Cri | 0.57 | 9.8 | 0.03 | Oct 7, 2019 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy… | ||
| CVE-2019-12689 | Hig | 0.57 | 8.8 | 0.03 | Oct 2, 2019 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient… | ||
| CVE-2019-12688 | Hig | 0.57 | 8.8 | 0.03 | Oct 2, 2019 | A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability… | ||
| CVE-2019-12687 | Hig | 0.57 | 8.8 | 0.03 | Oct 2, 2019 | A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability… | ||
| CVE-2019-16676 | Cri | 0.57 | 9.8 | 0.03 | Sep 30, 2019 | Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call. | ||
| CVE-2019-16142 | Cri | 0.57 | 9.8 | 0.02 | Sep 9, 2019 | An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application. | ||
| CVE-2019-13270 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it… | ||
| CVE-2019-13269 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with… | ||
| CVE-2019-13268 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To… | ||
| CVE-2019-15657 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2019 | In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. | ||
| CVE-2019-15324 | Hig | 0.57 | 8.8 | 0.03 | Aug 22, 2019 | The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. | ||
| CVE-2018-14671 | Cri | 0.57 | 9.8 | 0.03 | Aug 15, 2019 | In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability. | ||
| CVE-2019-10199 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain. | ||
| CVE-2016-10812 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117). | ||
| CVE-2016-10808 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). | ||
| CVE-2016-10805 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). | ||
| CVE-2016-10793 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). | ||
| CVE-2016-10789 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). | ||
| CVE-2016-10788 | Hig | 0.57 | 8.8 | 0.02 | Aug 6, 2019 | cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). | ||
| CVE-2017-18475 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204). |
- risk 0.57cvss 9.8epss 0.03
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy…
- risk 0.57cvss 8.8epss 0.03
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient…
- risk 0.57cvss 8.8epss 0.03
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability…
- risk 0.57cvss 8.8epss 0.03
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability…
- risk 0.57cvss 9.8epss 0.03
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.
- risk 0.57cvss 9.8epss 0.02
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.
- risk 0.57cvss 8.8epss 0.01
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it…
- risk 0.57cvss 8.8epss 0.01
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with…
- risk 0.57cvss 8.8epss 0.01
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To…
- risk 0.57cvss 9.8epss 0.02
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
- risk 0.57cvss 8.8epss 0.03
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
- risk 0.57cvss 9.8epss 0.03
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
- risk 0.57cvss 8.8epss 0.01
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
- risk 0.57cvss 8.8epss 0.01
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
- risk 0.57cvss 8.8epss 0.01
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
- risk 0.57cvss 8.8epss 0.02
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).