VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,384)

page 197 of 220
  • CVE-2026-31063MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the formArpBindConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-31062MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtpServerDirConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-31061MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ConfigAdvideo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-31060MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the formGroupConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-31058MedApr 6, 2026
    risk 0.29cvss 4.5epss 0.00

    UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-57275MedOct 1, 2025
    risk 0.29cvss 5.5epss 0.00

    Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.

  • CVE-2013-1424MedJun 26, 2025
    risk 0.29cvss 5.6epss 0.00

    Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.

  • CVE-2024-8882MedNov 12, 2024
    risk 0.29cvss 4.5epss 0.00

    A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.

  • CVE-2022-49041MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors.

  • CVE-2022-49040MedSep 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors.

  • CVE-2024-30799MedApr 22, 2024
    risk 0.29cvss 4.4epss 0.00

    An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.

  • CVE-2024-26889MedApr 17, 2024
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this…

  • CVE-2023-52346MedApr 8, 2024
    risk 0.29cvss 4.4epss 0.00

    In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

  • CVE-2024-27225MedMar 11, 2024
    risk 0.29cvss 4.4epss 0.00

    In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-32968MedDec 8, 2023
    risk 0.29cvss 4.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-4397MedNov 28, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series firmware version 5.37, and USG20(W)-VPN series firmware version 5.37, could allow an authenticated local attacker with administrator…

  • CVE-2023-46256MedOct 31, 2023
    risk 0.29cvss 4.4epss 0.01

    PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a…

  • CVE-2023-5139MedOct 26, 2023
    risk 0.29cvss 4.4epss 0.00

    Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver

  • CVE-2023-4163MedAug 31, 2023
    risk 0.29cvss 4.4epss 0.00

    In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.

  • CVE-2020-21469MedAug 22, 2023
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with…