CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,364)
page 16 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-7221 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2024 | A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer… | ||
| CVE-2023-33025 | Cri | 0.64 | 9.8 | 0.00 | Jan 2, 2024 | Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call. | ||
| CVE-2023-51771 | Cri | 0.64 | 9.8 | 0.01 | Dec 25, 2023 | In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI. | ||
| CVE-2023-50986 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. | ||
| CVE-2023-6906 | Cri | 0.64 | 9.8 | 0.02 | Dec 18, 2023 | A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag with the input ie8… | ||
| CVE-2023-50469 | Cri | 0.64 | 9.8 | 0.09 | Dec 15, 2023 | Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi. | ||
| CVE-2023-41913 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. | ||
| CVE-2023-33083 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2023 | Memory corruption in WLAN Host while processing RRM beacon on the AP. | ||
| CVE-2023-33082 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2023 | Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE. | ||
| CVE-2023-38823 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2023 | Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd. | ||
| CVE-2023-45616 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful… | ||
| CVE-2023-45615 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these… | ||
| CVE-2023-45614 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these… | ||
| CVE-2023-33045 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute. | ||
| CVE-2023-42299 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function. | ||
| CVE-2023-45797 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2023 | A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code. | ||
| CVE-2018-17878 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function. | ||
| CVE-2023-45199 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2023 | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. | ||
| CVE-2023-35803 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2023 | IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. | ||
| CVE-2023-40830 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length. |
- risk 0.64cvss 9.8epss 0.02
A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer…
- risk 0.64cvss 9.8epss 0.00
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
- risk 0.64cvss 9.8epss 0.01
In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
- risk 0.64cvss 9.8epss 0.02
A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag with the input ie8…
- risk 0.64cvss 9.8epss 0.09
Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.
- risk 0.64cvss 9.8epss 0.02
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in WLAN Host while processing RRM beacon on the AP.
- risk 0.64cvss 9.8epss 0.01
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
- risk 0.64cvss 9.8epss 0.02
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
- risk 0.64cvss 9.8epss 0.01
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.
- risk 0.64cvss 9.8epss 0.01
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
- risk 0.64cvss 9.8epss 0.02
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.