Detailedlikelihood: Highseverity: HighDraft
CAPEC-10Buffer Overflow via Environment Variables
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the adversary finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-120, CWE-302, CWE-118, CWE-119, CWE-74 (and 5 more). Related CAPEC pattern: [object Object].
Related weaknesses· 10
Related attack patterns· 1
Exploits10
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Improper Control of Resource Identifiers ('Resource Injection')cwe-99 | 100% | live |
| Weakness | Authentication Bypass by Assumed-Immutable Datacwe-302 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Compiler Optimization Removal or Modification of Security-critical Codecwe-733 | 100% | live |
| Weakness | Incorrect Access of Indexable Resource ('Range Error')cwe-118 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.