Standardlikelihood: Highseverity: Very HighDraft
CAPEC-100Overflow Buffers
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Very High
Description
Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an adversary. As a consequence, an adversary is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the adversaries' choice.
Related weaknesses· 6
Related attack patterns· 1
Exploits6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Calculation of Buffer Sizecwe-131 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
| Weakness | Buffer Access with Incorrect Length Valuecwe-805 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
| Weakness | Improper Validation of Array Indexcwe-129 | 100% | live |
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.