VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 130 of 219
  • CVE-2022-46527HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    ELSYS ERS 1.5 Sound v2.3.8 was discovered to contain a buffer overflow via the NFC data parser.

  • CVE-2023-38975HigAug 29, 2023
    risk 0.49cvss 7.5epss 0.01

    * Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.

  • CVE-2023-40998HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.02

    Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.

  • CVE-2023-40997HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.02

    Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.

  • CVE-2023-36481HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop.

  • CVE-2023-36198HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function.

  • CVE-2023-39745HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-39386HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.

  • CVE-2023-39389HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

  • CVE-2023-39388HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

  • CVE-2023-4055HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox <…

  • CVE-2023-37758HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.

  • CVE-2023-30383HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.

  • CVE-2023-31998HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.

  • CVE-2021-46896HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.

  • CVE-2023-36359HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-36354HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET…

  • CVE-2022-48501HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48497HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48490HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.