VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 131 of 219
  • CVE-2023-24584HigJun 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and…

  • CVE-2023-32763HigMay 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.

  • CVE-2021-46886HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46885HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46884HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46883HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46882HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46881HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-45345HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file.

  • CVE-2022-43507HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2021-44283HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system.

  • CVE-2023-22922HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device.

  • CVE-2022-44232HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.01

    libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.

  • CVE-2023-22917HigApr 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32,…

  • CVE-2023-22915HigApr 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30…

  • CVE-2023-27705HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.01

    APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.

  • CVE-2020-23257HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.

  • CVE-2023-26769HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c.

  • CVE-2023-26076HigMar 13, 2023
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when…

  • CVE-2023-27065HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.