CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,372)
page 102 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31979 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c. | ||
| CVE-2023-27957 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. | ||
| CVE-2023-30257 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2023 | A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root. | ||
| CVE-2023-29596 | Hig | 0.51 | 7.8 | 0.00 | Apr 26, 2023 | Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a denial of service via the paq8 function. | ||
| CVE-2023-25505 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2023 | NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authorization can cause a buffer overflow, which may lead to denial of service, information disclosure, or arbitrary code execution. | ||
| CVE-2021-33971 | Hig | 0.51 | 7.8 | 0.00 | Apr 19, 2023 | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting… | ||
| CVE-2021-33973 | Hig | 0.51 | 7.8 | 0.00 | Apr 19, 2023 | Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | ||
| CVE-2023-26733 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file. | ||
| CVE-2022-42431 | Hig | 0.51 | 7.8 | 0.00 | Mar 29, 2023 | This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the bcmdhd driver. The… | ||
| CVE-2022-33278 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. | ||
| CVE-2022-47664 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2023 | Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse | ||
| CVE-2021-33983 | Hig | 0.51 | 7.8 | 0.00 | Feb 17, 2023 | Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the error_ref_sym function. | ||
| CVE-2022-42274 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution. | ||
| CVE-2021-26409 | Hig | 0.51 | 7.8 | 0.00 | Jan 11, 2023 | Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secure Nested Paging) memory integrity. | ||
| CVE-2022-47663 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609 | ||
| CVE-2022-47658 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039 | ||
| CVE-2022-47657 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662 | ||
| CVE-2022-47656 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273 | ||
| CVE-2022-47654 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261 | ||
| CVE-2022-47653 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2023 | GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113 |
- risk 0.51cvss 7.8epss 0.00
Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a denial of service via the paq8 function.
- risk 0.51cvss 7.8epss 0.00
NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authorization can cause a buffer overflow, which may lead to denial of service, information disclosure, or arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting…
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file.
- risk 0.51cvss 7.8epss 0.00
This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the bcmdhd driver. The…
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
- risk 0.51cvss 7.8epss 0.00
Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the error_ref_sym function.
- risk 0.51cvss 7.8epss 0.00
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.
- risk 0.51cvss 7.8epss 0.00
Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secure Nested Paging) memory integrity.
- risk 0.51cvss 7.8epss 0.00
GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609
- risk 0.51cvss 7.8epss 0.00
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039
- risk 0.51cvss 7.8epss 0.00
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662
- risk 0.51cvss 7.8epss 0.00
GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273
- risk 0.51cvss 7.8epss 0.00
GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261
- risk 0.51cvss 7.8epss 0.00
GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113