Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2019-12-19 CVE-2019-19902 Improper Input Validation vulnerability in Backdropcms Backdrop CMS
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.
network
low complexity
backdropcms CWE-20
7.2
2019-12-18 CVE-2019-11108 Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-20
6.7
2019-12-18 CVE-2019-11107 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-20
critical
9.8
2019-12-18 CVE-2019-11104 Improper Input Validation vulnerability in Intel products
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-20
7.8
2019-12-18 CVE-2019-11103 Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware
Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-20
7.8
2019-12-18 CVE-2019-11102 Improper Input Validation vulnerability in Intel products
Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-20
4.4
2019-12-18 CVE-2019-11101 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-20
4.4
2019-12-18 CVE-2019-11100 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
low complexity
intel CWE-20
4.6
2019-12-18 CVE-2019-11088 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-20
8.8
2019-12-18 CVE-2019-11087 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
local
low complexity
intel CWE-20
6.7