CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,364)
page 13 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-9418 | Cri | 0.64 | 9.8 | 0.00 | Dec 2, 2024 | In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-48406 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2024 | Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c. | ||
| CVE-2024-52759 | Cri | 0.64 | 9.8 | 0.06 | Nov 19, 2024 | D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. | ||
| CVE-2024-52714 | Cri | 0.64 | 9.8 | 0.01 | Nov 19, 2024 | Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime. | ||
| CVE-2024-25254 | Cri | 0.64 | 9.8 | 0.00 | Nov 11, 2024 | SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter. | ||
| CVE-2024-50667 | Cri | 0.64 | 9.8 | 0.06 | Nov 11, 2024 | The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks. | ||
| CVE-2024-35426 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2024 | vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c. | ||
| CVE-2024-40494 | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2024 | Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet. | ||
| CVE-2024-48150 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2024 | D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function. | ||
| CVE-2024-45746 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2024 | An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer… | ||
| CVE-2024-46652 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function. | ||
| CVE-2024-40568 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2024 | Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component | ||
| CVE-2024-46419 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter. | ||
| CVE-2024-46451 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter. | ||
| CVE-2024-46045 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2024 | Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function. | ||
| CVE-2024-41433 | Cri | 0.64 | 9.8 | 0.01 | Sep 3, 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reproduction of this issue did… | ||
| CVE-2024-34198 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2024 | TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying… | ||
| CVE-2024-44555 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. | ||
| CVE-2024-41285 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2024 | A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path. | ||
| CVE-2024-45237 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a… |
- risk 0.64cvss 9.8epss 0.00
In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c.
- risk 0.64cvss 9.8epss 0.06
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
- risk 0.64cvss 9.8epss 0.00
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
- risk 0.64cvss 9.8epss 0.06
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.
- risk 0.64cvss 9.8epss 0.01
vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer…
- risk 0.64cvss 9.8epss 0.01
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component
- risk 0.64cvss 9.8epss 0.01
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
- risk 0.64cvss 9.8epss 0.01
Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
- risk 0.64cvss 9.8epss 0.01
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reproduction of this issue did…
- risk 0.64cvss 9.8epss 0.01
TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying…
- risk 0.64cvss 9.8epss 0.01
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.
- risk 0.64cvss 9.8epss 0.00
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a…