Detailedlikelihood: Highseverity: HighDraft
CAPEC-46Overflow Variables and Tags
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversary crafts a malicious HTML page or configuration file that includes oversized strings, thus causing an overflow.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-120, CWE-118, CWE-119, CWE-74, CWE-20 (and 3 more). Related CAPEC patterns: [object Object], [object Object], [object Object].
Related weaknesses· 8
Related attack patterns· 3
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Compiler Optimization Removal or Modification of Security-critical Codecwe-733 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Incorrect Access of Indexable Resource ('Range Error')cwe-118 | 100% | live |
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.