VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 191 of 220
  • CVE-2023-52551MedApr 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-29244MedMar 21, 2024
    risk 0.34cvss 5.3epss 0.00

    Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.

  • CVE-2023-52365MedFeb 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-6334MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.

  • CVE-2023-49993MedDec 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.

  • CVE-2023-49990MedDec 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.

  • CVE-2023-24548MedAug 29, 2023
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation…

  • CVE-2023-35979MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.01

    There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the…

  • CVE-2023-23494MedMay 8, 2023
    risk 0.34cvss 5.3epss 0.01

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service.

  • CVE-2023-1452MedMar 17, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this…

  • CVE-2021-25467MedOct 6, 2021
    risk 0.34cvss 5.3epss 0.00

    Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.

  • CVE-2020-7120MedFeb 23, 2021
    risk 0.34cvss 5.3epss 0.00

    A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful…

  • CVE-2026-68768MedAug 22, 2026
    risk 0.33cvss 6.1epss 0.00

    hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via…

  • CVE-2026-36189MedMay 21, 2026
    risk 0.33cvss 6.2epss 0.00

    Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial of service via the check_template.cpp, check_template function,…

  • CVE-2026-34866MedApr 13, 2026
    risk 0.33cvss 5.1epss 0.00

    Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-50361MedDec 3, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash.

  • CVE-2025-31712MedJun 3, 2025
    risk 0.33cvss 5.1epss 0.00

    In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.

  • CVE-2025-25529MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute…

  • CVE-2025-25528MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.04

    Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands…

  • CVE-2025-25527MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or…