VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 192 of 220
  • CVE-2025-25526MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary…

  • CVE-2025-25525MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute…

  • CVE-2025-25524MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or…

  • CVE-2024-54105MedDec 12, 2024
    risk 0.33cvss 5.1epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-50362MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-50361MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-25580MedMar 27, 2024
    risk 0.33cvss 6.2epss 0.00

    An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

  • CVE-2022-0636MedApr 22, 2022
    risk 0.33cvss 5.0epss 0.00

    A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.

  • CVE-2026-18103MedAug 5, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request.…

  • CVE-2025-25900MedFeb 13, 2025
    risk 0.32cvss 4.9epss 0.00

    A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2024-9197MedDec 3, 2024
    risk 0.32cvss 4.9epss 0.00

    A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS)…

  • CVE-2024-52755MedNov 21, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

  • CVE-2024-52757MedNov 20, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

  • CVE-2024-52754MedNov 20, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

  • CVE-2024-6343MedSep 3, 2024
    risk 0.32cvss 4.9epss 0.01

    A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware…

  • CVE-2024-27908MedApr 5, 2024
    risk 0.32cvss 4.9epss 0.01

    A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

  • CVE-2023-32975MedDec 8, 2023
    risk 0.32cvss 4.9epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-22924MedMay 1, 2023
    risk 0.32cvss 4.9epss 0.01

    A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device.

  • CVE-2022-42444MedFeb 12, 2023
    risk 0.32cvss 4.9epss 0.01

    IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow. A remote privileged user could overflow a buffer and cause the application to crash. IBM X-Force ID: 238538.

  • CVE-2021-28202MedApr 6, 2021
    risk 0.32cvss 4.9epss 0.02

    The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate…