VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 133 of 219
  • CVE-2022-46541HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the ssid parameter at /goform/fast_setting_wifi_set.

  • CVE-2022-46540HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/addressNat.

  • CVE-2022-46539HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security_5g parameter at /goform/WifiBasicSet.

  • CVE-2022-46537HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security parameter at /goform/WifiBasicSet.

  • CVE-2022-46536HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeedUp parameter at /goform/SetClientState.

  • CVE-2022-46535HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/SetClientState.

  • CVE-2022-46534HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.

  • CVE-2022-46533HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.

  • CVE-2022-46532HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.

  • CVE-2022-46531HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/addWifiMacFilter.

  • CVE-2022-46530HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

  • CVE-2022-45666HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

  • CVE-2022-45665HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

  • CVE-2022-45672HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.09

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.

  • CVE-2022-45671HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.

  • CVE-2022-45670HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

  • CVE-2022-45669HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.

  • CVE-2022-45664HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.

  • CVE-2022-45663HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

  • CVE-2022-45661HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.