Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-05-10 CVE-2022-32577 Improper Input Validation vulnerability in Intel products
Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local access
local
low complexity
intel CWE-20
6.0
2023-05-09 CVE-2021-46754 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.
network
low complexity
amd CWE-20
critical
9.1
2023-05-09 CVE-2021-46756 Improper Input Validation vulnerability in AMD products
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.
network
low complexity
amd CWE-20
critical
9.1
2023-05-09 CVE-2021-46773 Improper Input Validation vulnerability in AMD products
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
network
low complexity
amd CWE-20
8.8
2023-05-09 CVE-2021-46762 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
network
low complexity
amd CWE-20
critical
9.1
2023-05-09 CVE-2021-46769 Improper Input Validation vulnerability in AMD products
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
network
low complexity
amd CWE-20
8.8
2023-05-09 CVE-2021-46775 Improper Input Validation vulnerability in AMD products
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.
low complexity
amd CWE-20
6.8
2023-05-09 CVE-2022-23818 Improper Input Validation vulnerability in AMD products
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.
network
low complexity
amd CWE-20
7.5
2023-05-08 CVE-2023-27961 Improper Input Validation vulnerability in Apple products
Multiple validation issues were addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5
2023-05-08 CVE-2023-28200 Improper Input Validation vulnerability in Apple Iphone OS and Macos
A validation issue was addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5