VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 173 of 220
  • CVE-2018-25278MedApr 26, 2026
    risk 0.40cvss 6.2epss 0.00

    PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can paste a 6000-byte buffer into the Registration Name and Registration Key fields via the Help…

  • CVE-2018-25277MedApr 26, 2026
    risk 0.40cvss 6.2epss 0.00

    PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string to the folder path input field. Attackers can craft a payload exceeding 6000 bytes and paste it into the 'Folder with picture files' field…

  • CVE-2018-25275MedApr 26, 2026
    risk 0.40cvss 6.2epss 0.00

    Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can paste a 2000-byte payload into the Camera name and DID number fields during camera addition to trigger an…

  • CVE-2018-25273MedApr 26, 2026
    risk 0.40cvss 6.2epss 0.00

    CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submitting an oversized payload in the License Key field. Attackers can generate a malicious file containing 4000 bytes of data, paste it into the License Key input…

  • CVE-2018-25264MedApr 26, 2026
    risk 0.40cvss 6.2epss 0.00

    TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string. Attackers can generate a payload file containing 4000 bytes of data, paste it into the License Key field,…

  • CVE-2026-1679HigMar 28, 2026
    risk 0.40cvss 7.3epss 0.00

    The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploit requires local code that can call the socket send API; no remote attacker can…

  • CVE-2026-29976MedMar 26, 2026
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive information via the getradiotapfield() function

  • CVE-2026-28841MedMar 25, 2026
    risk 0.40cvss 6.2epss 0.00

    A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.

  • CVE-2026-30006MedMar 23, 2026
    risk 0.40cvss 6.2epss 0.00

    XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

  • CVE-2019-25326MedFeb 18, 2026
    risk 0.40cvss 6.2epss 0.00

    ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providing an oversized input in the Enter Key field. Attackers can generate a 256-byte buffer of repeated 'A' characters to trigger an application crash when pasting…

  • CVE-2020-37171MedFeb 7, 2026
    risk 0.40cvss 6.2epss 0.00

    TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and…

  • CVE-2020-37170MedFeb 7, 2026
    risk 0.40cvss 6.2epss 0.00

    TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address field with 3000 bytes of arbitrary data to trigger an application crash and…

  • CVE-2020-37166MedFeb 7, 2026
    risk 0.40cvss 6.2epss 0.00

    AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate.

  • CVE-2020-37165MedFeb 7, 2026
    risk 0.40cvss 6.2epss 0.00

    AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash.

  • CVE-2020-37164MedFeb 7, 2026
    risk 0.40cvss 6.2epss 0.00

    AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.

  • CVE-2020-37131MedFeb 5, 2026
    risk 0.40cvss 6.2epss 0.00

    Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the…

  • CVE-2020-36994MedJan 29, 2026
    risk 0.40cvss 6.2epss 0.00

    QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows local attackers to crash the application. Attackers can paste a 300-character buffer into the FTP server address field to trigger an application crash and prevent…

  • CVE-2022-50689MedDec 22, 2025
    risk 0.40cvss 6.2epss 0.00

    Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task…

  • CVE-2025-12142MedOct 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

  • CVE-2025-29482MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.