VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 154 of 219
  • CVE-2026-3081HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.00

    GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…

  • CVE-2026-2920HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.01

    GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-20436MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2025-47335MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while parsing clock configuration data for a specific hardware type.

  • CVE-2025-47334MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while processing shared command buffer packet between camera userspace and kernel.

  • CVE-2025-64182HigNov 10, 2025
    risk 0.44cvss 7.8epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through 3.2.4, 3.3.0 through 3.3.5, and 3.4.0 through 3.4.2, a memory safety bug in the legacy OpenEXR Python…

  • CVE-2025-54642MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54641MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54632MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2025-5828MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication…

  • CVE-2024-49829MedMay 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Memory corruption can occur during context user dumps due to inadequate checks on buffer length.

  • CVE-2024-44866MedMar 17, 2025
    risk 0.44cvss 6.8epss 0.00

    A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.

  • CVE-2025-21780HigFeb 27, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table() It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function…

  • CVE-2024-0144MedFeb 12, 2025
    risk 0.44cvss 6.8epss 0.01

    NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to data tampering.

  • CVE-2025-24153MedJan 27, 2025
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-47090HigJan 24, 2025
    risk 0.44cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns

  • CVE-2024-48806MedJan 9, 2025
    risk 0.44cvss 6.8epss 0.00

    Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field

  • CVE-2024-56456MedJan 8, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56453MedJan 8, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-40427HigJan 7, 2025
    risk 0.44cvss 7.9epss 0.00

    Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute