VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 210 of 219
  • CVE-2024-24474HigFeb 20, 2024
    risk 0.00cvss 8.8epss 0.01

    QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

  • CVE-2024-25196LowFeb 20, 2024
    risk 0.00cvss 3.3epss 0.00

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.

  • CVE-2022-48620CriJan 12, 2024
    risk 0.00cvss 9.8epss 0.01

    uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.

  • CVE-2023-48704HigDec 22, 2023
    risk 0.00cvss 7.0epss 0.01

    ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-50628CriDec 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.

  • CVE-2023-50044CriDec 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

  • CVE-2023-37457HigDec 14, 2023
    risk 0.00cvss 7.5epss 0.01

    Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the…

  • CVE-2023-42801HigDec 14, 2023
    risk 0.00cvss 7.6epss 0.01

    Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow…

  • CVE-2023-42800HigDec 14, 2023
    risk 0.00cvss 8.8epss 0.02

    Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds…

  • CVE-2023-42799HigDec 14, 2023
    risk 0.00cvss 8.8epss 0.02

    Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds…

  • CVE-2023-50268MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.00

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-50246MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.01

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-49208CriNov 23, 2023
    risk 0.00cvss 9.8epss 0.01

    scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.

  • CVE-2023-43887HigNov 22, 2023
    risk 0.00cvss 8.1epss 0.01

    Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.

  • CVE-2023-47471MedNov 16, 2023
    risk 0.00cvss 6.5epss 0.01

    Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component.

  • CVE-2023-47625LowNov 13, 2023
    risk 0.00cvss 2.9epss 0.01

    PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A malicious user may create an RC…

  • CVE-2023-46001MedNov 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.

  • CVE-2023-46852HigOct 27, 2023
    risk 0.00cvss 7.5epss 0.01

    In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

  • CVE-2023-36321HigOct 17, 2023
    risk 0.00cvss 7.5epss 0.01

    Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.

  • CVE-2023-40589MedAug 31, 2023
    risk 0.00cvss 4.3epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions there is a Global-Buffer-Overflow in the ncrush_decompress function. Feeding crafted input into this function can trigger the overflow which has only…