VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 103 of 219
  • CVE-2022-47095HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c

  • CVE-2022-47091HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c

  • CVE-2022-47089HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c

  • CVE-2022-47088HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.

  • CVE-2022-47087HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c

  • CVE-2022-42261HigDec 30, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

  • CVE-2022-40284HigNov 6, 2022
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to…

  • CVE-2021-34055HigNov 4, 2022
    risk 0.51cvss 7.8epss 0.00

    jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.

  • CVE-2022-43752HigOct 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Oracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation vulnerability. A low privileged user can escalate to root by crafting a malicious printer and double clicking on the the crafted printer's icon.

  • CVE-2022-33217HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile

  • CVE-2022-38510HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.

  • CVE-2022-30984HigAug 26, 2022
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow vulnerability in the Rubrik Backup Service (RBS) Agent for Linux or Unix-based systems in Rubrik CDM 7.0.1, 7.0.1-p1, 7.0.1-p2 or 7.0.1-p3 before CDM 7.0.2-p2 could allow a local attacker to obtain root privileges by sending a crafted message to the RBS agent.

  • CVE-2022-38236HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.

  • CVE-2022-35003HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    JPEGDEC commit be4843c was discovered to contain a global buffer overflow via ucDitherBuffer at /src/jpeg.inl.

  • CVE-2022-34998HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl.

  • CVE-2021-41413HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.

  • CVE-2021-35129HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure…

  • CVE-2021-35102HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2022-24701HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause a denial of service or possibly achieve code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2022-26754HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.