Detailedlikelihood: Highseverity: HighDraft
CAPEC-8Buffer Overflow in an API Call
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This attack targets libraries or shared code modules which are vulnerable to buffer overflow attacks. An adversary who has knowledge of known vulnerable libraries or shared code can easily target software that makes use of these libraries. All clients that make use of the code library thus become vulnerable by association. This has a very broad effect on security across a system, usually affecting more than one software process.
Related weaknesses· 8
Related attack patterns· 1
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Access of Indexable Resource ('Range Error')cwe-118 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Compiler Optimization Removal or Modification of Security-critical Codecwe-733 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.