VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 94 of 219
  • CVE-2018-25302HigApr 29, 2026
    risk 0.51cvss 7.8epss 0.00

    Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with…

  • CVE-2026-4153HigApr 11, 2026
    risk 0.51cvss 7.8epss 0.01

    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-21382HigApr 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption when handling power management requests with improperly sized input/output buffers.

  • CVE-2025-47389HigApr 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

  • CVE-2026-2034HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in…

  • CVE-2025-47399HigFeb 2, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.

  • CVE-2026-22184HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user…

  • CVE-2025-47394HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

  • CVE-2025-47388HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while passing pages to DSP with an unaligned starting address.

  • CVE-2025-47321HigDec 18, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while copying packets received from unix clients.

  • CVE-2025-10889HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-10887HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-10886HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-36931HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36930HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36928HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36927HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-47341HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    memory corruption while processing an image encoding completion event.

  • CVE-2025-21481HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while performing private key encryption in trusted application.

  • CVE-2025-21476HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.