VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 92 of 668
  • CVE-2023-36563MedKEVOct 10, 2023
    risk 0.56cvss 6.5epss 0.21

    Microsoft WordPad Information Disclosure Vulnerability

  • CVE-2023-3769HigOct 2, 2023
    risk 0.56cvss 8.6epss 0.01

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when…

  • CVE-2023-3768HigOct 2, 2023
    risk 0.56cvss 8.6epss 0.01

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when…

  • CVE-2023-36761MedKEVSep 12, 2023
    risk 0.56cvss 6.5epss 0.19

    Microsoft Word Information Disclosure Vulnerability

  • CVE-2022-36392HigAug 11, 2023
    risk 0.56cvss 8.6epss 0.01

    Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via…

  • CVE-2023-28649HigMay 22, 2023
    risk 0.56cvss 8.6epss 0.01

    The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives…

  • CVE-2023-28302HigApr 11, 2023
    risk 0.56cvss 7.5epss 0.93

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-26067HigApr 10, 2023
    risk 0.56cvss 8.1epss 0.38

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

  • CVE-2023-20072HigMar 23, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the…

  • CVE-2022-4904HigMar 6, 2023
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

  • CVE-2023-20020HigJan 20, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …

  • CVE-2023-22496HigJan 14, 2023
    risk 0.56cvss 8.1epss 0.36

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. When an alert is triggered, the function…

  • CVE-2022-3752HigDec 19, 2022
    risk 0.56cvss 8.6epss 0.01

    An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes…

  • CVE-2022-3157HigDec 16, 2022
    risk 0.56cvss 8.6epss 0.01

    A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).

  • CVE-2022-40265HigNov 30, 2022
    risk 0.56cvss 8.6epss 0.01

    Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote…

  • CVE-2022-31766HigOct 11, 2022
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.1.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router…

  • CVE-2014-0144HigSep 29, 2022
    risk 0.56cvss 8.6epss 0.01

    QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host…

  • CVE-2022-33719HigAug 5, 2022
    risk 0.56cvss 8.6epss 0.00

    Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

  • CVE-2022-25161HigMay 18, 2022
    risk 0.56cvss 8.6epss 0.04

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80,…

  • CVE-2022-20745HigMay 3, 2022
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This…