CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92
CVEs mapped to this weakness (4,371)
page 23 of 219| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45721 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function. | ||
| CVE-2022-45720 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function. | ||
| CVE-2022-45719 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function. | ||
| CVE-2022-45718 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function. | ||
| CVE-2022-45716 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function. | ||
| CVE-2022-45715 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function. | ||
| CVE-2022-45714 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function. | ||
| CVE-2022-45712 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function. | ||
| CVE-2022-45710 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function. | ||
| CVE-2022-45708 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function. | ||
| CVE-2022-45707 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function. | ||
| CVE-2022-45706 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2022 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function. | ||
| CVE-2022-44283 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | AVS Audio Converter 10.3 is vulnerable to Buffer Overflow. | ||
| CVE-2022-44183 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic. | ||
| CVE-2022-44180 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter. | ||
| CVE-2022-44178 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB. | ||
| CVE-2022-44177 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart. | ||
| CVE-2022-44176 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic. | ||
| CVE-2022-44175 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. | ||
| CVE-2022-44174 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName. |
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.
- risk 0.64cvss 9.8epss 0.01
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.
- risk 0.64cvss 9.8epss 0.01
AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.