Detailedlikelihood: Highseverity: HighDraft
CAPEC-24Filter Failure through Buffer Overflow
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
Related weaknesses· 8
Related attack patterns· 1
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Incorrect Access of Indexable Resource ('Range Error')cwe-118 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
| Weakness | Compiler Optimization Removal or Modification of Security-critical Codecwe-733 | 100% | live |
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.