VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,491)

page 10 of 225
  • CVE-2025-67073CriDec 17, 2025
    risk 0.64cvss 9.8epss 0.01

    A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to…

  • CVE-2025-65834CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By setting these values to extremely large numbers, the application attempts to allocate excessive memory…

  • CVE-2025-50401CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.

  • CVE-2025-50398CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password.

  • CVE-2023-53874CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.00

    GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

  • CVE-2025-14709CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.06

    A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the argument params leads to buffer overflow.…

  • CVE-2025-14708CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.06

    A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow.…

  • CVE-2025-14535CriDec 11, 2025
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly…

  • CVE-2025-14534CriDec 11, 2025
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manipulation of the argument NatBind can lead to buffer overflow. The attack can be launched…

  • CVE-2025-11780CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is…

  • CVE-2025-50402CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

  • CVE-2025-50399CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

  • CVE-2025-60554CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard.

  • CVE-2025-60553CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard52.

  • CVE-2025-60548CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

  • CVE-2025-55613CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

  • CVE-2025-29365CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

  • CVE-2025-8760CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

  • CVE-2025-8854CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd…

  • CVE-2025-51630CriJul 17, 2025
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.