VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 74 of 219
  • CVE-2023-43822HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43821HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43820HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43819HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-43818HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

  • CVE-2023-40250HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893.

  • CVE-2023-50245CriDec 11, 2023
    risk 0.57cvss 9.8epss 0.01

    OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

  • CVE-2023-49468HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.

  • CVE-2023-47004HigNov 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

  • CVE-2022-34886HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.

  • CVE-2023-35056HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the…

  • CVE-2023-35055HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the…

  • CVE-2023-4582HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability…

  • CVE-2023-42277CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.

  • CVE-2023-42276CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.

  • CVE-2020-25887HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

  • CVE-2020-24295HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.

  • CVE-2020-24293HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file.

  • CVE-2020-24292HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

  • CVE-2023-39550HigAug 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function.