VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 18 of 219
  • CVE-2023-39666CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.

  • CVE-2023-39665CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.

  • CVE-2023-37734CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

  • CVE-2023-28561CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in QESL while processing payload from external ESL device to firmware.

  • CVE-2023-3346CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In…

  • CVE-2023-35982CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35981CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35980CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35802CriJul 15, 2023
    risk 0.64cvss 9.8epss 0.01

    IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to…

  • CVE-2023-37793CriJul 14, 2023
    risk 0.64cvss 9.8epss 0.01

    WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.

  • CVE-2023-34561CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.

  • CVE-2020-25969CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.01

    gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().

  • CVE-2023-26616CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.

  • CVE-2023-26612CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

  • CVE-2020-20703CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

  • CVE-2023-35856CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.

  • CVE-2023-35855CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

  • CVE-2023-34832CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.

  • CVE-2023-2686CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

  • CVE-2023-1329CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.