VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 161 of 220
  • CVE-2019-20712MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R6250 before 1.0.4.34, R6300v2…

  • CVE-2014-8271MedFeb 6, 2020
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.

  • CVE-2014-9629HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

  • CVE-2014-9628HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

  • CVE-2014-9625HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a…

  • CVE-2019-18397HigNov 13, 2019
    risk 0.44cvss 7.8epss 0.02

    A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then…

  • CVE-2026-20782MedMay 12, 2026
    risk 0.43cvss 6.6epss 0.00

    Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.…

  • CVE-2025-32732MedNov 11, 2025
    risk 0.43cvss 6.6epss 0.00

    Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may…

  • CVE-2025-21426MedJul 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing camera TPG write request.

  • CVE-2024-53013MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption may occur while processing voice call registration with user.

  • CVE-2024-49830MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing an IOCTL call to set mixer controls.

  • CVE-2024-12343MedDec 8, 2024
    risk 0.43cvss 6.5epss 0.05

    A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType leads to buffer overflow.…

  • CVE-2024-32228MedJul 1, 2024
    risk 0.43cvss 6.6epss 0.00

    FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

  • CVE-2023-43515MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.

  • CVE-2023-28539MedOct 3, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.

  • CVE-2021-44864MedFeb 8, 2022
    risk 0.43cvss 6.5epss 0.10

    TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userRpm/PingIframeRpm.htm request which contains redundant & in parameter.

  • CVE-2020-19719MedJul 13, 2021
    risk 0.43cvss 6.5epss 0.06

    A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS).

  • CVE-2020-35776MedFeb 18, 2021
    risk 0.43cvss 6.5epss 0.04

    A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.

  • CVE-2020-14355MedOct 7, 2020
    risk 0.43cvss 6.6epss 0.03

    Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send…

  • CVE-2018-17770MedSep 9, 2020
    risk 0.43cvss 6.6epss 0.01

    Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.