In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a he
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function n
A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.
A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup
A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-00
Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged
Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulne
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Aut
Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privile
Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox ent
In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due
In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due t
An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due t
Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerabilit
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary
sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions aroun
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the cust
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafte
In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input valida
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload
Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. in Snapdr
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin di
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sendin
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a de
A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before ve
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the refe
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker t
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started