VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,371)

page 27 of 219
  • CVE-2022-35161CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.01

    GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.

  • CVE-2022-31209CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand.

  • CVE-2021-37778CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.

  • CVE-2022-31784CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient…

  • CVE-2021-35104CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-35081CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2022-29797CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation.

  • CVE-2021-37404CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2022-24702CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the…

  • CVE-2022-29246CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass…

  • CVE-2022-30055CriMay 16, 2022
    risk 0.64cvss 9.8epss 0.04

    Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.

  • CVE-2022-29591CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

  • CVE-2022-28994CriApr 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.

  • CVE-2022-28480CriApr 29, 2022
    risk 0.64cvss 9.8epss 0.02

    ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

  • CVE-2021-43636CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in the HTTP request process.

  • CVE-2022-22687CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2021-45756CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

  • CVE-2021-44632CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44631CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44630CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.