CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 99 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30690 | Hig | 0.55 | 8.5 | 0.00 | Oct 4, 2023 | Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-24853 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while registering for key provisioning notify. | ||
| CVE-2023-30664 | Hig | 0.55 | 8.5 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30658 | Hig | 0.55 | 8.5 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30656 | Hig | 0.55 | 8.5 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities. | ||
| CVE-2023-30655 | Hig | 0.55 | 8.5 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-26128 | Hig | 0.55 | 8.4 | 0.01 | May 27, 2023 | All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the… | ||
| CVE-2023-28291 | Hig | 0.55 | 8.4 | 0.01 | Apr 11, 2023 | Raw Image Extension Remote Code Execution Vulnerability | ||
| CVE-2023-21439 | Hig | 0.55 | 8.5 | 0.00 | Feb 9, 2023 | Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-33300 | Hig | 0.55 | 8.4 | 0.00 | Jan 9, 2023 | Memory corruption in Automotive Android OS due to improper input validation. | ||
| CVE-2022-39266 | Cri | 0.55 | 9.6 | 0.01 | Sep 29, 2022 | isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process.… | ||
| CVE-2022-2856 | Med | 0.55 | 6.5 | 0.05 | KEV | Sep 26, 2022 | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. | |
| CVE-2022-33704 | Hig | 0.55 | 8.5 | 0.00 | Jul 12, 2022 | Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-33703 | Hig | 0.55 | 8.5 | 0.00 | Jul 12, 2022 | Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-30756 | Hig | 0.55 | 8.5 | 0.00 | Jul 12, 2022 | Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder. | ||
| CVE-2022-30754 | Hig | 0.55 | 8.5 | 0.00 | Jul 12, 2022 | Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker. | ||
| CVE-2022-30713 | Hig | 0.55 | 8.5 | 0.00 | Jun 7, 2022 | Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-30712 | Hig | 0.55 | 8.5 | 0.00 | Jun 7, 2022 | Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-30711 | Hig | 0.55 | 8.5 | 0.00 | Jun 7, 2022 | Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-30710 | Hig | 0.55 | 8.5 | 0.00 | Jun 7, 2022 | Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities. |
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in HLOS while registering for key provisioning notify.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.4epss 0.01
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the…
- risk 0.55cvss 8.4epss 0.01
Raw Image Extension Remote Code Execution Vulnerability
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Android OS due to improper input validation.
- risk 0.55cvss 9.6epss 0.01
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process.…
- risk 0.55cvss 6.5epss 0.05
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.
- risk 0.55cvss 8.5epss 0.00
Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.