CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,364)
page 17 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43131 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow. | ||
| CVE-2023-36109 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2023 | Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c. | ||
| CVE-2023-42320 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2023 | Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function. | ||
| CVE-2023-36659 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication). | ||
| CVE-2020-19320 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login. | ||
| CVE-2020-19319 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login. | ||
| CVE-2023-41064 | Hig | 0.64 | 7.8 | 0.15 | KEV | Sep 7, 2023 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to… | |
| CVE-2023-28562 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2023 | Memory corruption while handling payloads from remote ESL. | ||
| CVE-2023-36187 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. | ||
| CVE-2023-4041 | Cri | 0.64 | 9.8 | 0.00 | Aug 23, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This… | ||
| CVE-2023-39749 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request. | ||
| CVE-2023-39747 | Cri | 0.64 | 9.8 | 0.08 | Aug 21, 2023 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm. | ||
| CVE-2023-39454 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code. | ||
| CVE-2023-39674 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39673 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | ||
| CVE-2023-39672 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39671 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68. | ||
| CVE-2023-39670 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets. | ||
| CVE-2023-39668 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function. | ||
| CVE-2023-39667 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function. |
- risk 0.64cvss 9.8epss 0.01
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
- risk 0.64cvss 7.8epss 0.15
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to…
- risk 0.64cvss 9.8epss 0.00
Memory corruption while handling payloads from remote ESL.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
- risk 0.64cvss 9.8epss 0.00
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…
- risk 0.64cvss 9.8epss 0.01
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.
- risk 0.64cvss 9.8epss 0.08
TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
- risk 0.64cvss 9.8epss 0.01
Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.