VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 95 of 219
  • CVE-2025-8892HigSep 22, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-39727HigSep 7, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix potential buffer overflow in setup_clusters() In setup_swap_map(), we only ensure badpages are in range (0, last_page]. As maxpages might be < last_page, setup_clusters() will encounter a buffer…

  • CVE-2025-5048HigAug 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-6634HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-5038HigJul 29, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-5037HigJul 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-27058HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing packet data with exceedingly large packet.

  • CVE-2025-27052HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing data packets in diag received from Unix clients.

  • CVE-2025-27043HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing manipulated payload in video firmware.

  • CVE-2025-21445HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host.

  • CVE-2025-21444HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while copying the result to the transmission queue in EMAC.

  • CVE-2025-44952HigJun 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater than 101.

  • CVE-2025-5601HigJun 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file

  • CVE-2025-5548HigJun 4, 2025
    risk 0.51cvss 7.3epss 0.12

    A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-46714HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a extremely large copy into the…

  • CVE-2025-46713HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have an arithmetic overflow deep in the memory allocation subsystem that would lead to a smaller…

  • CVE-2025-37891HigMay 19, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow at UMP SysEx message conversion The conversion function from MIDI 1.0 to UMP packet contains an internal buffer to keep the incoming MIDI bytes, and its size is 4, as it was…

  • CVE-2025-1253HigMay 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before…

  • CVE-2025-37803HigMay 8, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmabuf creation by casting size_limit_mb to u64 when calculate pglimit.

  • CVE-2025-4255HigMay 5, 2025
    risk 0.51cvss 7.3epss 0.02

    A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the…