VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 211 of 219
  • CVE-2023-41361CriAug 29, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

  • CVE-2021-32422HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array.

  • CVE-2020-28840HigAug 11, 2023
    risk 0.00cvss 7.8epss 0.00

    Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).

  • CVE-2023-39976CriAug 8, 2023
    risk 0.00cvss 9.8epss 0.01

    log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

  • CVE-2022-28550CriJun 13, 2023
    risk 0.00cvss 9.8epss 0.01

    Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer…

  • CVE-2023-2597HigMay 22, 2023
    risk 0.00cvss 7.0epss 0.00

    In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.

  • CVE-2023-27892LowMay 2, 2023
    risk 0.00cvss 3.8epss 0.00

    Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messages. Flaws in cf_confirmExecTx() in ethereum_contracts.c can be used to reveal arbitrary microcontroller memory on the device screen or…

  • CVE-2023-2241MedApr 22, 2023
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has…

  • CVE-2023-28772MedMar 23, 2023
    risk 0.00cvss 6.7epss 0.01

    An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

  • CVE-2023-28116HigMar 17, 2023
    risk 0.00cvss 8.1epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system. The network stack of Contiki-NG uses a global buffer…

  • CVE-2023-26768HigMar 16, 2023
    risk 0.00cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions.

  • CVE-2023-26767HigMar 16, 2023
    risk 0.00cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint.

  • CVE-2020-27507CriMar 15, 2023
    risk 0.00cvss 9.8epss 0.01

    The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.

  • CVE-2023-27590HigMar 14, 2023
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. In version 0.5.1 and prior, converting a GDB registers profile file into a Rizin register profile can result in a stack-based buffer overflow when the `name`, `type`, or `groups` fields have longer…

  • CVE-2023-27585HigMar 14, 2023
    risk 0.00cvss 7.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is…

  • CVE-2023-0996HigFeb 24, 2023
    risk 0.00cvss 7.8epss 0.00

    There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

  • CVE-2021-37311HigFeb 3, 2023
    risk 0.00cvss 7.5epss 0.01

    Buffer Overflow vulnerability in fcitx5 5.0.8 allows attackers to cause a denial of service via crafted message to the application's listening port.

  • CVE-2023-23143HigJan 20, 2023
    risk 0.00cvss 7.8epss 0.00

    Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av_parsers.c. GPAC version 2.3-DEV-rev1-g4669ba229-master.

  • CVE-2023-22745MedJan 19, 2023
    risk 0.00cvss 6.4epss 0.01

    tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an…

  • CVE-2023-22741CriJan 19, 2023
    risk 0.00cvss 9.8epss 0.02

    Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in…