VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 132 of 219
  • CVE-2023-27064HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2023-27062HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2022-33213HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Memory corruption in modem due to buffer overflow while processing a PPP packet

  • CVE-2023-26075HigMar 10, 2023
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to…

  • CVE-2022-48260HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.00

    There is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions.

  • CVE-2023-22422HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management…

  • CVE-2023-0617HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in TRENDNet TEW-811DRU 1.0.10.0. It has been classified as critical. This affects an unknown part of the file /wireless/guestnetwork.asp of the component httpd. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely.…

  • CVE-2023-0612HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. Affected is an unknown function of the file /wireless/basic.asp of the component httpd. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2023-22416HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On all MX Series and SRX Series platform with SIP ALG enabled, when a malformed SIP packet is received, the flow…

  • CVE-2023-22399HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    When sFlow is enabled and it monitors a packet forwarded via ECMP, a buffer management vulnerability in the dcpfe process of Juniper Networks Junos OS on QFX10K Series systems allows an attacker to cause the Packet Forwarding Engine (PFE) to crash and restart by sending specific…

  • CVE-2022-46551HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the time parameter at /goform/saveParentControlInfo.

  • CVE-2022-46550HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.

  • CVE-2022-46549HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/saveParentControlInfo.

  • CVE-2022-46548HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/DhcpListClient.

  • CVE-2022-46547HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.

  • CVE-2022-46546HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/RouteStatic.

  • CVE-2022-46545HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

  • CVE-2022-46544HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the cmdinput parameter at /goform/exeCommand.

  • CVE-2022-46543HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mitInterface parameter at /goform/addressNat.

  • CVE-2022-46542HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/addressNat.