VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 185 of 220
  • CVE-2021-4214MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.01

    A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

  • CVE-2022-32406MedJul 14, 2022
    risk 0.36cvss 5.5epss 0.01

    GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a Denial of Service (DoS) via a crafted MAP file.

  • CVE-2022-30552MedJun 8, 2022
    risk 0.36cvss 5.5epss 0.00

    Das U-Boot 2022.01 has a Buffer Overflow.

  • CVE-2022-27242MedMay 20, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.

  • CVE-2022-1110MedMay 18, 2022
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.

  • CVE-2022-30067MedMay 17, 2022
    risk 0.36cvss 5.5epss 0.01

    GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

  • CVE-2021-30331MedApr 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-45429MedFeb 4, 2022
    risk 0.36cvss 5.5epss 0.01

    A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service.

  • CVE-2022-24130MedJan 31, 2022
    risk 0.36cvss 5.5epss 0.02

    xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

  • CVE-2021-41496MedDec 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative…

  • CVE-2021-36333MedNov 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Dell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially exploit this vulnerability, leading to an application crash.

  • CVE-2020-23902MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.

  • CVE-2020-23900MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address controls Code Flow starting at Editor!TMethodImplementationIntercept+0x57a3b.

  • CVE-2020-23890MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted JPG file. Related to Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at JPGCodec+0x753648.

  • CVE-2020-23884MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow in Nomacs v3.15.0 allows attackers to cause a denial of service (DoS) via a crafted MNG file.

  • CVE-2021-27722MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.

  • CVE-2021-0421MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue…

  • CVE-2020-21534MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

  • CVE-2020-21532MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

  • CVE-2020-21531MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.