Metalikelihood: Highseverity: Very HighDraft

CAPEC-123Buffer Manipulation

Abstraction
Meta
Status
Draft
Likelihood
High
Severity
Very High

Description

An adversary manipulates an application's interaction with a buffer in an attempt to read or modify data they shouldn't have access to. Buffer attacks are distinguished in that it is the buffer space itself that is the target of the attack rather than any code responsible for interpreting the content of the buffer. In virtually all buffer attacks the content that is placed in the buffer is immaterial. Instead, most buffer attacks involve retrieving or providing more input than can be stored in the allocated buffer, resulting in the reading or overwriting of other unintended program memory.

Related weaknesses· 1

CWE-119

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Operations within the Bounds of a Memory Buffercwe-119100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Overflow Buffers
CAPEC
Overread Buffers
CAPEC
Buffer Overflow via Parameter Expansion
CAPEC
Pointer Manipulation
CAPEC
Buffer Overflow via Environment Variables
CAPEC
Client-side Injection-induced Buffer Overflow
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.