CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,384)
page 184 of 220| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24736 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script. | ||
| CVE-2022-47464 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47463 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47362 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47336 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47335 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2023-26924 | Med | 0.36 | 5.5 | 0.00 | Mar 27, 2023 | LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior." | ||
| CVE-2023-24809 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have… | ||
| CVE-2022-39118 | Med | 0.36 | 5.5 | 0.00 | Jan 4, 2023 | In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-46824 | Med | 0.36 | 5.6 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | ||
| CVE-2022-42760 | Med | 0.36 | 5.5 | 0.00 | Dec 6, 2022 | In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services. | ||
| CVE-2022-42756 | Med | 0.36 | 5.5 | 0.00 | Dec 6, 2022 | In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2021-33897 | Med | 0.36 | 5.5 | 0.00 | Nov 17, 2022 | A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to cause a denial of service (application crash) via a crafted MIDI file with malformed bytes. This file is mishandled during a deletion attempt. In Synthesia before… | ||
| CVE-2022-39343 | Med | 0.36 | 5.6 | 0.01 | Nov 8, 2022 | Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory… | ||
| CVE-2022-39122 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39121 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39120 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-36647 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2022 | PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at source/common/header.cc:269. | ||
| CVE-2021-23172 | Med | 0.36 | 5.5 | 0.00 | Aug 25, 2022 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash. | ||
| CVE-2021-23159 | Med | 0.36 | 5.5 | 0.00 | Aug 25, 2022 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash. |
- risk 0.36cvss 5.5epss 0.00
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior."
- risk 0.36cvss 5.5epss 0.00
NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have…
- risk 0.36cvss 5.5epss 0.00
In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to cause a denial of service (application crash) via a crafted MIDI file with malformed bytes. This file is mishandled during a deletion attempt. In Synthesia before…
- risk 0.36cvss 5.6epss 0.01
Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory…
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at source/common/header.cc:269.
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.