CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,372)
page 130 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46527 | Hig | 0.49 | 7.5 | 0.01 | Sep 1, 2023 | ELSYS ERS 1.5 Sound v2.3.8 was discovered to contain a buffer overflow via the NFC data parser. | ||
| CVE-2023-38975 | Hig | 0.49 | 7.5 | 0.01 | Aug 29, 2023 | * Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component. | ||
| CVE-2023-40998 | Hig | 0.49 | 7.5 | 0.02 | Aug 28, 2023 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component. | ||
| CVE-2023-40997 | Hig | 0.49 | 7.5 | 0.02 | Aug 28, 2023 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet. | ||
| CVE-2023-36481 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2023 | An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop. | ||
| CVE-2023-36198 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2023 | Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function. | ||
| CVE-2023-39745 | Hig | 0.49 | 7.5 | 0.01 | Aug 21, 2023 | TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2023-39386 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | ||
| CVE-2023-39389 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-39388 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-4055 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2023 | When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox <… | ||
| CVE-2023-37758 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2023 | D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi. | ||
| CVE-2023-30383 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2023 | TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data. | ||
| CVE-2023-31998 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2023 | A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices. | ||
| CVE-2021-46896 | Hig | 0.49 | 7.5 | 0.01 | Jul 6, 2023 | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332. | ||
| CVE-2023-36359 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2023-36354 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET… | ||
| CVE-2022-48501 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48497 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48490 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability. |
- risk 0.49cvss 7.5epss 0.01
ELSYS ERS 1.5 Sound v2.3.8 was discovered to contain a buffer overflow via the NFC data parser.
- risk 0.49cvss 7.5epss 0.01
* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.
- risk 0.49cvss 7.5epss 0.02
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.
- risk 0.49cvss 7.5epss 0.02
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function.
- risk 0.49cvss 7.5epss 0.01
TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.01
When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox <…
- risk 0.49cvss 7.5epss 0.01
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
- risk 0.49cvss 7.5epss 0.01
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
- risk 0.49cvss 7.5epss 0.01
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
- risk 0.49cvss 7.5epss 0.01
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET…
- risk 0.49cvss 7.5epss 0.00
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.