VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 158 of 220
  • CVE-2023-26318MedOct 11, 2023
    risk 0.44cvss 6.7epss 0.01

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.

  • CVE-2023-22384MedOct 3, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).

  • CVE-2022-3742MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.

  • CVE-2023-4029MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-4028MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-34419MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-21649MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in WLAN while running doDriverCmd for an unspecific command.

  • CVE-2021-43072MedJul 18, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7…

  • CVE-2023-21640MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux when the file upload API is called with parameters having large buffer.

  • CVE-2023-21639MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.

  • CVE-2023-21635MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.

  • CVE-2022-33230MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host

  • CVE-2022-33226MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.

  • CVE-2022-33224MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.

  • CVE-2023-0977MedApr 3, 2023
    risk 0.44cvss 6.7epss 0.01

    A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable.

  • CVE-2023-20624MedMar 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628530; Issue ID: ALPS07628530.

  • CVE-2022-40137MedJan 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-1892MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

  • CVE-2022-1891MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

  • CVE-2022-25712MedDec 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables