VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,364)

page 9 of 219
  • CVE-2025-14709CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.06

    A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the argument params leads to buffer overflow.…

  • CVE-2025-14708CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.06

    A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow.…

  • CVE-2025-14535CriDec 11, 2025
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly…

  • CVE-2025-14534CriDec 11, 2025
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manipulation of the argument NatBind can lead to buffer overflow. The attack can be launched…

  • CVE-2025-11780CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is…

  • CVE-2025-50402CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

  • CVE-2025-50399CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

  • CVE-2025-60554CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard.

  • CVE-2025-60553CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard52.

  • CVE-2025-60548CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

  • CVE-2025-55613CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

  • CVE-2025-29365CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

  • CVE-2025-8760CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

  • CVE-2025-8854CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd…

  • CVE-2025-51630CriJul 17, 2025
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.

  • CVE-2025-7673CriJul 16, 2025
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a…

  • CVE-2023-38036CriJul 12, 2025
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.

  • CVE-2015-0843CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.00

    yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

  • CVE-2025-6098CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy of the file /goform/setSysAdm of the component API. The manipulation of the argument passwd1 leads to buffer overflow. It is possible to initiate the…

  • CVE-2025-46060CriJun 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component