VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 17 of 219
  • CVE-2023-43131CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.

  • CVE-2023-36109CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

  • CVE-2023-42320CriSep 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.

  • CVE-2023-36659CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).

  • CVE-2020-19320CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.

  • CVE-2020-19319CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.

  • CVE-2023-41064HigKEVSep 7, 2023
    risk 0.64cvss 7.8epss 0.15

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to…

  • CVE-2023-28562CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption while handling payloads from remote ESL.

  • CVE-2023-36187CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.

  • CVE-2023-4041CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…

  • CVE-2023-39749CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.

  • CVE-2023-39747CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.08

    TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm.

  • CVE-2023-39454CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.

  • CVE-2023-39674CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.

  • CVE-2023-39673CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().

  • CVE-2023-39672CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.

  • CVE-2023-39671CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.

  • CVE-2023-39670CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.

  • CVE-2023-39668CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.

  • CVE-2023-39667CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.