VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 196 of 220
  • CVE-2022-20879MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20878MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20877MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20876MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20875MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20874MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20873MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2025-25458MedApr 15, 2025
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

  • CVE-2025-25453MedApr 15, 2025
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

  • CVE-2024-58110MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58109MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58108MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58106MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-35106MedFeb 7, 2025
    risk 0.30cvss 4.6epss 0.01

    NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.

  • CVE-2024-25373MedFeb 15, 2024
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.

  • CVE-2023-0687MedFeb 6, 2023
    risk 0.30cvss 4.6epss 0.01

    A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix…

  • CVE-2021-34557MedJun 10, 2021
    risk 0.30cvss 4.6epss 0.00

    XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically…

  • CVE-2026-31623MedApr 24, 2026
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() A malicious USB device claiming to be a CDC Phonet modem can overflow the skb_shared_info->frags[] array by sending an unbounded sequence of…

  • CVE-2026-31066MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-31065MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formConfigCliForEngineerOnly function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.