VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 187 of 220
  • CVE-2020-8720MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.00

    Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2020-16302MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16301MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16298MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16294MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16288MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-3344MedMay 22, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An…

  • CVE-2020-3343MedMay 22, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An…

  • CVE-2020-10814MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in Code::Blocks 17.12 allows an attacker to execute arbitrary code via a crafted project file.

  • CVE-2020-0501MedMar 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Buffer overflow in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2019-5258MedDec 13, 2019
    risk 0.36cvss 5.5epss 0.00

    Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a buffer overflow vulnerability. An attacker who logs…

  • CVE-2019-5257MedDec 13, 2019
    risk 0.36cvss 5.5epss 0.00

    Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace) have a resource management vulnerability. An attacker who logs in to the board may send crafted messages from the internal network.

  • CVE-2019-19489MedDec 2, 2019
    risk 0.36cvss 5.5epss 0.01

    SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.

  • CVE-2019-5247MedNov 29, 2019
    risk 0.36cvss 5.5epss 0.00

    Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific parameter and send to the process to exploit this vulnerability. Successfully exploit may cause service crash.

  • CVE-2008-3275MedAug 12, 2008
    risk 0.36cvss 5.5epss 0.01

    The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of…

  • CVE-2026-19969MedAug 17, 2026
    risk 0.35cvss 5.4epss 0.00

    A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model Output Mesh Generator.…

  • CVE-2025-68383MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a…

  • CVE-2025-41707MedOct 14, 2025
    risk 0.35cvss 5.3epss 0.01

    The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue without affecting the core functionality.

  • CVE-2025-41706MedOct 14, 2025
    risk 0.35cvss 5.3epss 0.02

    The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to trigger the issue without affecting the core functionality.

  • CVE-2024-56805MedJun 6, 2025
    risk 0.35cvss 5.4epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the…