VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 12 of 219
  • CVE-2025-0960CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.

  • CVE-2024-53320CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.00

    Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.

  • CVE-2024-55194CriJan 23, 2025
    risk 0.64cvss 9.8epss 0.01

    OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.

  • CVE-2024-57703CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.

  • CVE-2025-22916CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

  • CVE-2025-22913CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.

  • CVE-2025-22907CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

  • CVE-2025-22904CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

  • CVE-2024-57483CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.

  • CVE-2024-57473CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.01

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST…

  • CVE-2024-57482CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.01

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by…

  • CVE-2024-57480CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.01

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST…

  • CVE-2024-57479CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.01

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST…

  • CVE-2024-57471CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.01

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by…

  • CVE-2025-22946CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

  • CVE-2018-4301CriJan 8, 2025
    risk 0.64cvss 9.8epss 0.01

    This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.

  • CVE-2024-52061CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Queuing Service, Recording Service, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before…

  • CVE-2024-55564CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

  • CVE-2024-37863CriDec 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.

  • CVE-2024-37861CriDec 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.