CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
11,842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 176 of 237
- CVE-2023-20528LOWCVSS 2.4EG 2.42023-01-11
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
- CVE-2023-20530HIGHCVSS 7.5EG 7.52023-01-11
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
- CVE-2023-20532MEDIUMCVSS 5.3EG 5.32023-01-11
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
- CVE-2023-20560MEDIUMCVSS 4.4EG 4.42023-08-15
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. …
- CVE-2023-20564MEDIUMCVSS 6.7EG 6.72023-08-15
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel exe…
- CVE-2023-20606MEDIUMCVSS 4.4EG 4.42023-02-06
In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS075711…
- CVE-2023-20612MEDIUMCVSS 6.7EG 6.72023-02-06
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762957…
- CVE-2023-20613MEDIUMCVSS 6.7EG 6.72023-02-06
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762861…
- CVE-2023-20621MEDIUMCVSS 6.7EG 6.72023-03-07
In tinysys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076…
- CVE-2023-20626MEDIUMCVSS 6.7EG 6.72023-03-07
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS074…
- CVE-2023-20634MEDIUMCVSS 6.7EG 6.72023-03-07
In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2023-20636MEDIUMCVSS 6.7EG 6.72023-03-07
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2023-20637MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762858…
- CVE-2023-20638MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762853…
- CVE-2023-20639MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762858…
- CVE-2023-20640MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762957…
- CVE-2023-20641MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762957…
- CVE-2023-20642MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762858…
- CVE-2023-20643MEDIUMCVSS 6.7EG 6.72023-03-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762858…
- CVE-2023-20644MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628603;…
- CVE-2023-20645MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628609;…
- CVE-2023-20646MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628536;…
- CVE-2023-20647MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628547;…
- CVE-2023-20648MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612;…
- CVE-2023-20649MEDIUMCVSS 4.4EG 4.42023-03-07
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628607;…
- CVE-2023-20650MEDIUMCVSS 6.7EG 6.72023-03-07
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762957…
- CVE-2023-20651MEDIUMCVSS 4.4EG 4.42023-03-07
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629576;…
- CVE-2023-20704MEDIUMCVSS 5.5EG 5.52023-05-15
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20705MEDIUMCVSS 5.5EG 5.52023-05-15
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20707MEDIUMCVSS 6.7EG 6.72023-05-15
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762855…
- CVE-2023-20708MEDIUMCVSS 6.7EG 6.72023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20709MEDIUMCVSS 4.4EG 4.42023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-2071CRITICALCVSS 9.8EG 9.82023-09-12
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the func…
- CVE-2023-20710MEDIUMCVSS 4.4EG 4.42023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20718MEDIUMCVSS 6.7EG 6.72023-05-15
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0764518…
- CVE-2023-20719MEDIUMCVSS 4.4EG 4.42023-05-15
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20720MEDIUMCVSS 6.7EG 6.72023-05-15
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-20721MEDIUMCVSS 6.7EG 6.72023-05-15
In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0716…
- CVE-2023-20722MEDIUMCVSS 6.7EG 6.72023-05-15
In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0777…
- CVE-2023-20932LOWCVSS 3.3EG 3.32023-02-28
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-20960HIGHCVSS 8.8EG 8.82023-03-24
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges neede…
- CVE-2023-20976HIGHCVSS 7.3EG 7.32023-03-24
In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no addition…
- CVE-2023-21092HIGHCVSS 7.8EG 7.82023-04-19
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no…
- CVE-2023-21111MEDIUMCVSS 5.5EG 5.52023-05-15
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges nee…
- CVE-2023-21121HIGHCVSS 7.8EG 7.82023-06-15
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution …
- CVE-2023-21135HIGHCVSS 7.8EG 7.82023-06-15
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2023-21136MEDIUMCVSS 5.5EG 5.52023-06-15
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is no…
- CVE-2023-21138HIGHCVSS 7.8EG 7.82023-06-15
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges…
- CVE-2023-21143MEDIUMCVSS 5.5EG 5.52023-06-15
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is n…
- CVE-2023-21192HIGHCVSS 7.8EG 7.82023-06-28
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no addition…
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →