VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 184 of 220
  • CVE-2020-24736MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.

  • CVE-2022-47464MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

  • CVE-2022-47463MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

  • CVE-2022-47362MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

  • CVE-2022-47336MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

  • CVE-2022-47335MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

  • CVE-2023-26924MedMar 27, 2023
    risk 0.36cvss 5.5epss 0.00

    LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior."

  • CVE-2023-24809MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have…

  • CVE-2022-39118MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-46824MedDec 8, 2022
    risk 0.36cvss 5.6epss 0.00

    In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.

  • CVE-2022-42760MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42756MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2021-33897MedNov 17, 2022
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to cause a denial of service (application crash) via a crafted MIDI file with malformed bytes. This file is mishandled during a deletion attempt. In Synthesia before…

  • CVE-2022-39343MedNov 8, 2022
    risk 0.36cvss 5.6epss 0.01

    Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory…

  • CVE-2022-39122MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39121MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39120MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-36647MedSep 2, 2022
    risk 0.36cvss 5.5epss 0.00

    PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at source/common/header.cc:269.

  • CVE-2021-23172MedAug 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.

  • CVE-2021-23159MedAug 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.