CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,364)
page 18 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39666 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters. | ||
| CVE-2023-39665 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter. | ||
| CVE-2023-37734 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow. | ||
| CVE-2023-28561 | Cri | 0.64 | 9.8 | 0.00 | Aug 8, 2023 | Memory corruption in QESL while processing payload from external ESL device to firmware. | ||
| CVE-2023-3346 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In… | ||
| CVE-2023-35982 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-35981 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-35980 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2023 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of… | ||
| CVE-2023-35802 | Cri | 0.64 | 9.8 | 0.01 | Jul 15, 2023 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to… | ||
| CVE-2023-37793 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2023 | WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp. | ||
| CVE-2023-34561 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level. | ||
| CVE-2020-25969 | Cri | 0.64 | 9.8 | 0.01 | Jul 5, 2023 | gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). | ||
| CVE-2023-26616 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo. | ||
| CVE-2023-26612 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo. | ||
| CVE-2020-20703 | Cri | 0.64 | 9.8 | 0.02 | Jun 20, 2023 | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter. | ||
| CVE-2023-35856 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet. | ||
| CVE-2023-35855 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable. | ||
| CVE-2023-34832 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | ||
| CVE-2023-2686 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack. | ||
| CVE-2023-1329 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. |
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
- risk 0.64cvss 9.8epss 0.01
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in QESL while processing payload from external ESL device to firmware.
- risk 0.64cvss 9.8epss 0.02
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.02
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…
- risk 0.64cvss 9.8epss 0.01
IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to…
- risk 0.64cvss 9.8epss 0.01
WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.
- risk 0.64cvss 9.8epss 0.02
A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.
- risk 0.64cvss 9.8epss 0.01
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
- risk 0.64cvss 9.8epss 0.01
A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.
- risk 0.64cvss 9.8epss 0.01
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.
- risk 0.64cvss 9.8epss 0.01
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
- risk 0.64cvss 9.8epss 0.01
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.