VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,371)

page 23 of 219
  • CVE-2022-45721CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.

  • CVE-2022-45720CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.

  • CVE-2022-45719CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.

  • CVE-2022-45718CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.

  • CVE-2022-45716CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.

  • CVE-2022-45715CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function.

  • CVE-2022-45714CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.

  • CVE-2022-45712CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

  • CVE-2022-45710CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

  • CVE-2022-45708CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.

  • CVE-2022-45707CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.

  • CVE-2022-45706CriDec 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.

  • CVE-2022-44283CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

  • CVE-2022-44183CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

  • CVE-2022-44180CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.

  • CVE-2022-44178CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.

  • CVE-2022-44177CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.

  • CVE-2022-44176CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.

  • CVE-2022-44175CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

  • CVE-2022-44174CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.