CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,372)
page 100 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28741 | Hig | 0.51 | 7.9 | 0.00 | Nov 14, 2023 | Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-33055 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Audio while invoking callback function in driver from ADSP. | ||
| CVE-2023-33031 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | ||
| CVE-2023-46587 | Hig | 0.51 | 7.8 | 0.00 | Oct 27, 2023 | Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file. | ||
| CVE-2023-43250 | Hig | 0.51 | 7.8 | 0.01 | Oct 18, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution. | ||
| CVE-2023-43896 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2023 | A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code. | ||
| CVE-2023-33035 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory corruption while invoking callback function of AFE from ADSP. | ||
| CVE-2023-43907 | Hig | 0.51 | 7.8 | 0.01 | Oct 1, 2023 | OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c. | ||
| CVE-2023-39063 | Hig | 0.51 | 7.8 | 0.00 | Sep 11, 2023 | Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard. | ||
| CVE-2023-32379 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.4. An app may be able to execute arbitrary code with kernel privileges. | ||
| CVE-2023-32356 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28215 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28214 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28213 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28212 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28211 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28210 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28209 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | ||
| CVE-2023-28560 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | ||
| CVE-2023-28559 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. |
- risk 0.51cvss 7.9epss 0.00
Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Audio while invoking callback function in driver from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
- risk 0.51cvss 7.8epss 0.01
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking callback function of AFE from ADSP.
- risk 0.51cvss 7.8epss 0.01
OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.4. An app may be able to execute arbitrary code with kernel privileges.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.