VYPR

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

BaseIncompleteLikelihood: High

Description

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (4,372)

page 99 of 219
  • CVE-2023-51798HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.

  • CVE-2023-51793HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

  • CVE-2024-26797HigApr 4, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent potential buffer overflow in map_hw_resources Adds a check in the map_hw_resources function to prevent a potential buffer overflow. The function was accessing arrays using an index…

  • CVE-2023-6175HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.03

    NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

  • CVE-2024-28583HigMar 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.

  • CVE-2024-28569HigMar 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.

  • CVE-2023-52612HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before copying from the scomp_scratch->dst to avoid req->dst buffer overflow problem.

  • CVE-2024-23286HigMar 8, 2024
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing an image may lead…

  • CVE-2021-47040HigFeb 28, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: io_uring: fix overflows checks in provide buffers Colin reported before possible overflow and sign extension problems in io_provide_buffers_prep(). As Linus pointed out previous attempt did nothing useful, see…

  • CVE-2024-20723HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2024-25165HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.01

    A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

  • CVE-2024-22749HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.01

    GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

  • CVE-2024-22919HigJan 19, 2024
    risk 0.51cvss 7.8epss 0.00

    swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.

  • CVE-2024-22912HigJan 19, 2024
    risk 0.51cvss 7.8epss 0.00

    A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.

  • CVE-2023-32401HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. Parsing an office document may lead to an unexpected app termination or arbitrary code execution.

  • CVE-2023-38583HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-33085HigJan 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in wearables while processing data from AON.

  • CVE-2023-33087HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Core while processing RX intent request.

  • CVE-2023-33017HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

  • CVE-2023-28546HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in SPS Application while exporting public key in sorter TA.