VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 170 of 220
  • CVE-2020-22024MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

  • CVE-2020-22021MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22020MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-22019MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-35224MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.

  • CVE-2020-24501MedFeb 17, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2020-4869MedJan 11, 2021
    risk 0.42cvss 6.5epss 0.02

    IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.

  • CVE-2020-28005MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.02

    httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial of service) by sending a POST request to the /admin/syslog endpoint. Fixed version: TL-WPA4220(EU)_V4_201023

  • CVE-2020-9238MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a buffer overflow vulnerability. A function in a module does not verify inputs sufficiently. Attackers can exploit this vulnerability by sending specific request. This could compromise normal service of the affected…

  • CVE-2020-5136MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal, which leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7,…

  • CVE-2020-15532MedAug 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

  • CVE-2020-4465MedJul 28, 2020
    risk 0.42cvss 6.5epss 0.02

    IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buffer using an older client and cause a denial of service. IBM…

  • CVE-2020-0576MedApr 15, 2020
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow in Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2020-6999MedMar 26, 2020
    risk 0.42cvss 6.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer.

  • CVE-2014-1617MedFeb 13, 2020
    risk 0.42cvss 6.5epss 0.01

    Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of service.

  • CVE-2019-16336MedFeb 12, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload length larger than the configured link layer maximum RX payload size, which allows attackers (in radio range) to cause a denial of service…

  • CVE-2019-19196MedFeb 12, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices accepts a pairing request with a key size greater than 16…

  • CVE-2019-17520MedFeb 10, 2020
    risk 0.42cvss 6.5epss 0.02

    The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.

  • CVE-2019-17518MedFeb 10, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to link layer packets with a payload length larger than expected, allowing attackers in radio range to cause a buffer overflow via a crafted packet. This affects,…

  • CVE-2019-17061MedFeb 10, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within…