VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 206 of 219
  • CVE-2026-58553MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58552MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58551MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58550MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58549MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-51808CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.00

    Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp

  • CVE-2025-8412LowJul 14, 2026
    risk 0.00cvss epss 0.00

    A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this…

  • CVE-2026-15543HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-15484HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation results in buffer overflow. It is possible to launch the attack remotely. The vendor explains:…

  • CVE-2026-15483HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.00

    A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation of the argument nslookup_target leads to buffer overflow. It is possible to initiate the…

  • CVE-2026-57246HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash.

  • CVE-2026-52191HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444C8C component

  • CVE-2026-52189HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487330 component

  • CVE-2026-52187HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_483ba0 component

  • CVE-2026-57278HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57277HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57276HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57275HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57274HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57273HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…