VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 96 of 219
  • CVE-2025-46397HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

  • CVE-2025-29625HigApr 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.

  • CVE-2025-1277HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-21443HigApr 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing message content in eAVB.

  • CVE-2025-1660HigApr 1, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2022-49754HigMar 27, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() Smatch Warning: net/bluetooth/mgmt_util.c:375 mgmt_mesh_add() error: __memcpy() 'mesh_tx->param' too small (48 vs 50) Analysis: 'mesh_tx->param' is array…

  • CVE-2025-27835HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

  • CVE-2025-27834HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

  • CVE-2025-27833HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

  • CVE-2025-27830HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

  • CVE-2025-1430HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-2017HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that…

  • CVE-2025-0689HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the…

  • CVE-2024-43055HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing camera use case IOCTL call.

  • CVE-2024-57510HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

  • CVE-2024-57509HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

  • CVE-2024-0146HigJan 28, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.

  • CVE-2024-50664HigJan 23, 2025
    risk 0.51cvss 7.8epss 0.00

    gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.

  • CVE-2018-9387HigJan 18, 2025
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-45547HigJan 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.