VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 99 of 668
  • CVE-2023-30690HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-24853HigOct 3, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in HLOS while registering for key provisioning notify.

  • CVE-2023-30664HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30658HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30656HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2023-30655HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-26128HigMay 27, 2023
    risk 0.55cvss 8.4epss 0.01

    All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the…

  • CVE-2023-28291HigApr 11, 2023
    risk 0.55cvss 8.4epss 0.01

    Raw Image Extension Remote Code Execution Vulnerability

  • CVE-2023-21439HigFeb 9, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2022-33300HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Android OS due to improper input validation.

  • CVE-2022-39266CriSep 29, 2022
    risk 0.55cvss 9.6epss 0.01

    isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process.…

  • CVE-2022-2856MedKEVSep 26, 2022
    risk 0.55cvss 6.5epss 0.05

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

  • CVE-2022-33704HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-33703HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30756HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

  • CVE-2022-30754HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.

  • CVE-2022-30713HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30712HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30711HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30710HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.