CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,372)
page 131 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24584 | Hig | 0.49 | 7.5 | 0.01 | Jun 1, 2023 | Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and… | ||
| CVE-2023-32763 | Hig | 0.49 | 7.5 | 0.01 | May 28, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered. | ||
| CVE-2021-46886 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-46885 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-46884 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-46883 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-46882 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-46881 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2023 | The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-45345 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file. | ||
| CVE-2022-43507 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access. | ||
| CVE-2021-44283 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system. | ||
| CVE-2023-22922 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2023 | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device. | ||
| CVE-2022-44232 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2023 | libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427. | ||
| CVE-2023-22917 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32,… | ||
| CVE-2023-22915 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30… | ||
| CVE-2023-27705 | Hig | 0.49 | 7.5 | 0.01 | Apr 17, 2023 | APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. | ||
| CVE-2020-23257 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2023 | Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c. | ||
| CVE-2023-26769 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2023 | Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c. | ||
| CVE-2023-26076 | Hig | 0.49 | 7.6 | 0.01 | Mar 13, 2023 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when… | ||
| CVE-2023-27065 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2023 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
- risk 0.49cvss 7.5epss 0.01
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file.
- risk 0.49cvss 7.5epss 0.01
Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.
- risk 0.49cvss 7.5epss 0.01
A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system.
- risk 0.49cvss 7.5epss 0.01
A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device.
- risk 0.49cvss 7.5epss 0.01
libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.
- risk 0.49cvss 7.5epss 0.01
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32,…
- risk 0.49cvss 7.5epss 0.01
A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30…
- risk 0.49cvss 7.5epss 0.01
APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c.
- risk 0.49cvss 7.6epss 0.01
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when…
- risk 0.49cvss 7.5epss 0.01
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.