CWE-184

Incomplete List of Disallowed Inputs

Parent: CWE-693 - Protection Mechanism Failure

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

122 vulnerabilities with CWE-184
CVE-2021-31370 MEDIUM
Juniper Junos OS QFX5000/EX4600 <21.1R2 DoS via High-Rate Multicast Traffic
CVSS 6.5
CVE-2021-25737 LOW
Kubernetes 1.16.0-1.18.18 - Unauthenticated Private Network Traffic Redirection via EndpointSlice IP Validation Bypass
CVSS 2.7
CVE-2021-25631 HIGH
LibreOffice <7.1.2 & <7.0.5 - Code Injection
CVSS 8.8
CVE-2021-1135 MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated Unauthorized Data Access via REST API
CVSS 4.6
CVE-2021-1255 MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated REST API Authorization Bypass
CVSS 4.6
CVE-2021-1133 MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated REST API Authorization Bypass
CVSS 4.6
CVE-2020-14372 HIGH
GRUB2 < 2.06 - Secure Boot Bypass via ACPI Table Injection
CVSS 7.5
CVE-2020-3384 HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated OS Command Injection via REST API
CVSS 8.2
CVE-2020-5253 LOW
NetHack < 3.6.0 - Arbitrary Code Execution via Configuration File Escape Sequence
CVSS 3.9
CVE-2019-9212 CRITICAL
SOFA-Hessian < 4.0.2 - Remote Code Execution via Hessian Deserialization
CVSS 9.8
CVE-2018-16863 HIGH
Ghostscript 9.07 - Remote Code Execution via PostScript Document
CVSS 7.3
CVE-2018-7489 CRITICAL
jackson-databind < 2.7.9.3, 2.8.0-2.8.11.1, < 2.9.5 - Remote Code Execution via Deserialization Bypass
CVSS 9.8
CVE-2018-6383 HIGH
Monstra CMS < 3.0.4 - Authenticated Remote Code Execution via .pht or .phar File Upload
CVSS 8.8
CVE-2018-5968 HIGH
FasterXML jackson-databind <2.8.11, 2.9.x<2.9.3 - RCE
CVSS 8.1
CVE-2017-2602 LOW
Jenkins <2.44, 2.32.2 - Info Disclosure
CVSS 3.1
CVE-2017-7525 CRITICAL
jackson-databind <2.6.7.1, <2.7.9.1, <2.8.9 - Code Injection
CVSS 9.8
CVE-2017-15095 CRITICAL
jackson-databind <2.8.10, 2.9.1 - Code Injection
CVSS 9.8
CVE-2017-0909 CRITICAL
Private_address_check <0.4.1 - SSRF
CVSS 9.8
CVE-2017-7540 CRITICAL
rubygem-safemode <1.3.2 - Privilege Escalation
CVSS 9.8
CVE-2016-7076 MEDIUM
sudo < 1.8.18 - Privilege Escalation via wordexp() Argument Bypass
CVSS 6.4
CVE-2016-6189 MEDIUM
SOGo < 2.3.12 and 3.x < 3.1.1 - Authenticated Information Disclosure via Calendar Feed Fields
CVSS 4.3
CVE-2015-5946 HIGH
SuiteCRM 7.2.2 - Code Injection
CVSS 7.8
Details
Vulnerabilities 122