VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 101 of 219
  • CVE-2023-28544HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.

  • CVE-2023-21664HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in Core Platform while printing the response buffer in log.

  • CVE-2023-21662HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Core Platform while printing the response buffer in log.

  • CVE-2023-40031HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing…

  • CVE-2020-22219HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.01

    Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

  • CVE-2020-21428HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

  • CVE-2020-21427HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.01

    Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

  • CVE-2020-21426HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

  • CVE-2021-28835HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

  • CVE-2021-28427HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.

  • CVE-2020-24222HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.

  • CVE-2023-29414HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.

  • CVE-2023-24851HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while parsing QMI response message from firmware.

  • CVE-2023-22386HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.

  • CVE-2023-36377HigJul 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary code via a crafted .exe, .sys, and .dll files.

  • CVE-2023-36183HigJul 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.

  • CVE-2023-32384HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. Processing an image may lead to arbitrary code…

  • CVE-2023-23539HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

  • CVE-2023-36243HigJun 22, 2023
    risk 0.51cvss 7.8epss 0.00

    FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c.

  • CVE-2023-21135HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…