VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 11 of 219
  • CVE-2025-26004CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.

  • CVE-2025-26002CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.

  • CVE-2025-27836CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.

  • CVE-2025-27832CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

  • CVE-2025-27831CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

  • CVE-2025-29137CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.

  • CVE-2025-25567CriMar 12, 2025
    risk 0.64cvss 9.8epss 0.01

    SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,

  • CVE-2025-25565CriMar 12, 2025
    risk 0.64cvss 9.8epss 0.01

    SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long string on a command line.

  • CVE-2024-51139CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and…

  • CVE-2025-25678CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

  • CVE-2025-25676CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

  • CVE-2025-25674CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.

  • CVE-2025-25668CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.

  • CVE-2025-25667CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

  • CVE-2025-25664CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

  • CVE-2025-25663CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.

  • CVE-2025-25662CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.

  • CVE-2023-46271CriFeb 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

  • CVE-2025-25343CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

  • CVE-2025-25530CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the remote target device to…