VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 148 of 219
  • CVE-2025-25522HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.

  • CVE-2024-37044HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…

  • CVE-2024-37041HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…

  • CVE-2024-50131HigNov 5, 2024
    risk 0.47cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validating the event length strlen() returns a string length excluding the null byte. If the string length equals to the maximum buffer length, the buffer will have no…

  • CVE-2024-41176HigAug 27, 2024
    risk 0.47cvss 7.3epss 0.00

    The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.

  • CVE-2022-23817HigAug 13, 2024
    risk 0.47cvss epss 0.00

    Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.

  • CVE-2024-5974HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

  • CVE-2022-48681HigMay 28, 2024
    risk 0.47cvss 7.2epss 0.00

    Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

  • CVE-2024-25724HigMay 21, 2024
    risk 0.47cvss 7.3epss 0.00

    In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's…

  • CVE-2024-21480HigMay 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while playing audio file having large-sized input buffer.

  • CVE-2024-26768HigApr 3, 2024
    risk 0.47cvss 7.2epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC] With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these platforms.…

  • CVE-2024-21463HigApr 1, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while processing Codec2 during v13k decoder pitch synthesis.

  • CVE-2023-43548HigMar 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while parsing qcp clip with invalid chunk data size.

  • CVE-2023-6881HigFeb 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Possible buffer overflow in is_mount_point

  • CVE-2023-43519HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

  • CVE-2024-0338HigFeb 2, 2024
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).

  • CVE-2024-0645HigJan 17, 2024
    risk 0.47cvss 7.3epss 0.00

    Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records.

  • CVE-2023-7222HigJan 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer…

  • CVE-2023-38671HigJul 26, 2023
    risk 0.47cvss 8.3epss 0.01

    Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

  • CVE-2022-41029HigJan 26, 2023
    risk 0.47cvss 7.2epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…