VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 15 of 219
  • CVE-2024-35099CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2024-34945CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

  • CVE-2024-33874CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

  • CVE-2024-29159CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2022-32504CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a…

  • CVE-2023-46012CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

  • CVE-2024-32017CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.01

    RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the `gcoap_dns_server_proxy_get()` function contains a small typo that may lead to a buffer overflow in the…

  • CVE-2024-3871CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.02

    The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote…

  • CVE-2024-30620CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

  • CVE-2024-30635CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.

  • CVE-2024-30602CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

  • CVE-2024-30584CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

  • CVE-2024-30593CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

  • CVE-2024-29243CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.

  • CVE-2024-28639CriMar 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.

  • CVE-2021-47107CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow,…

  • CVE-2023-28582CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.

  • CVE-2023-52370CriFeb 18, 2024
    risk 0.64cvss 9.8epss 0.00

    Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.

  • CVE-2023-51885CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.

  • CVE-2023-52103CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.