VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 88 of 219
  • CVE-2025-52870HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52869HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52868HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-48725HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-48724HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-48723HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52872HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-52864HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-52863HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-14310CriDec 9, 2025
    risk 0.53cvss epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects rethinkdb: before 2.4.4.

  • CVE-2025-31701HigJul 23, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed…

  • CVE-2025-31700HigJul 23, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed…

  • CVE-2025-24003HigJul 8, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

  • CVE-2025-50263HigJul 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.

  • CVE-2025-50258HigJul 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.

  • CVE-2024-50697HigJan 24, 2025
    risk 0.53cvss 8.1epss 0.00

    In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.

  • CVE-2024-33453HigOct 17, 2024
    risk 0.53cvss 8.1epss 0.01

    Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.

  • CVE-2023-52946HigSep 26, 2024
    risk 0.53cvss 8.2epss 0.01

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial buffers and crash the client via unspecified vectors.

  • CVE-2024-42040HigAug 23, 2024
    risk 0.53cvss 8.1epss 0.01

    Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on…

  • CVE-2024-39207HigJun 27, 2024
    risk 0.53cvss 8.2epss 0.01

    lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.