VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 120 of 219
  • CVE-2020-37195HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37194HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an…

  • CVE-2020-37193HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when…

  • CVE-2020-37191HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and…

  • CVE-2020-37190HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input…

  • CVE-2020-37189HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash.

  • CVE-2020-37188HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become…

  • CVE-2020-37187HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37185HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application…

  • CVE-2020-37180HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.

  • CVE-2020-37179HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an…

  • CVE-2020-37175HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the Camera ID input field. Attackers can paste a 257-character buffer into the Camera ID field to trigger an application crash on iOS devices.

  • CVE-2020-37155HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without…

  • CVE-2020-37109HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an…

  • CVE-2020-37107HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the…

  • CVE-2020-37130HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the…

  • CVE-2020-36995HigJan 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the user configuration input. Attackers can overwrite the 'User' field with 350 bytes of repeated characters to trigger an application crash…

  • CVE-2021-47815HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash.

  • CVE-2021-47814HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential…

  • CVE-2021-47813HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a large buffer of 256 repeated characters into the registration key field to trigger…