Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-131 (缓冲区大小计算不正确) — Vulnerability Class 96

96 vulnerabilities classified as CWE-131 (缓冲区大小计算不正确). AI Chinese analysis included.

CWE-131 represents a critical logic error where software fails to accurately determine the necessary memory allocation size for a buffer. This miscalculation typically stems from using incorrect data types, ignoring header overhead, or neglecting null terminators during size computations. Attackers exploit this vulnerability by crafting inputs that exceed the allocated memory space, triggering a buffer overflow. This overflow allows malicious actors to overwrite adjacent memory, potentially executing arbitrary code, crashing the application, or gaining unauthorized system access. To prevent such exploits, developers must rigorously validate input lengths and employ safe, bounds-checking functions like strncpy or snprintf instead of unsafe alternatives. Additionally, utilizing static analysis tools and conducting thorough code reviews can help identify arithmetic errors in memory allocation logic before deployment, ensuring that buffer sizes accurately reflect the actual data requirements.

MITRE CWE Description
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Common Consequences (1)
Integrity, Availability, Confidentiality DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Read Memory, Modify Memory
If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing a…
Mitigations (5)
Implementation When allocating a buffer for the purpose of transforming, converting, or encoding an input, allocate enough memory to handle the largest possible encoding. For example, in a routine that converts "&" characters to "&" for HTML entity encoding, the output buffer needs to be at least 5 times as large as the input buffer.
Implementation Understand the programming language's underlying representation and how it interacts with numeric calculation (CWE-681). Pay close attention to byte size discrepancies, precision, signed/unsigned distinctions, truncation, conversion and casting between types, "not-a-number" calculations, and how the language handles numbers that are too large or too small for its underlying representation. [REF-7]…
Implementation Perform input validation on any numeric input by ensuring that it is within the expected range. Enforce that the input meets both the minimum and maximum requirements for the expected range.
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Implementation When processing structured incoming data containing a size field followed by raw data, identify and resolve any inconsistencies between the size field and the actual size of the data (CWE-130).
Examples (2)
The following code allocates memory for a maximum number of widgets. It then gets a user-specified number of widgets, making sure that the user does not request too many. It then initializes the elements of the array using InitializeWidget(). Because the number of widgets can vary for each request, the code inserts a NULL pointer to signify the location of the last widget.
int i; unsigned int numWidgets; Widget **WidgetList; numWidgets = GetUntrustedSizeValue(); if ((numWidgets == 0) || (numWidgets > MAX_NUM_WIDGETS)) { ExitError("Incorrect number of widgets requested!"); } WidgetList = (Widget **)malloc(numWidgets * sizeof(Widget *)); printf("WidgetList ptr=%p\n", WidgetList); for(i=0; i<numWidgets; i++) { WidgetList[i] = InitializeWidget(); } WidgetList[numWidgets] = NULL; showWidgets(WidgetList);
Bad · C
The following image processing code allocates a table for images.
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...
Bad · C
CVE ID Title CVSS Severity Published
CVE-2025-52955 Junos OS and Junos OS Evolved: When jflow/sflow is configured continuous logical interface flaps causes rpd crash and restart — Junos OS 6.5 Medium 2025-07-11
CVE-2025-27042 Incorrect Calculation of Buffer Size in Video — Snapdragon 7.8 High 2025-07-08
CVE-2025-46723 OpenVM byte decomposition of pc in AUIPC chip can overflow — openvm 9.8AI Critical AI 2025-05-02
CVE-2025-46688 QuickJS 安全漏洞 — QuickJS 5.6 Medium 2025-04-27
CVE-2025-46393 ImageMagick 安全漏洞 — ImageMagick 2.9 Low 2025-04-23
CVE-2025-43965 ImageMagick 安全漏洞 — ImageMagick 2.9 Low 2025-04-23
CVE-2025-1861 Stream HTTP wrapper truncates redirect location to 1024 bytes — PHP 6.5 - 2025-03-30
CVE-2025-30334 OpenBSD wg(4) kernel crash — OpenBSD 6.5 Medium 2025-03-20
CVE-2025-0395 GNU C Library 安全漏洞 — glibc 9.8 - 2025-01-22
CVE-2024-11425 Schneider Electric Modicon M580 安全漏洞 — Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety) 7.5 High 2025-01-17
CVE-2024-8361 DoS caused due to wrong hash length returned for SHA2/224 algorithm — WiSeConnect SDK 7.5 High 2025-01-07
CVE-2024-28052 LevelOne WBR-6012 安全漏洞 — WBR-6012 5.3 Medium 2024-10-30
CVE-2024-39808 Controller 6000和Controller 7000 安全漏洞 — Controller 6000 and Controller 7000 4.6 Medium 2024-09-11
CVE-2024-45287 Multiple vulnerabilities in libnv — FreeBSD 7.5AI High AI 2024-09-05
CVE-2024-5000 CODESYS: Incorrect calculation of buffer size can cause DoS on CODESYS OPC UA products — CODESYS Control for BeagleBone SL 7.5 High 2024-06-04
CVE-2024-30405 Junos OS: SRX 5000 Series with SPC2: Processing of specific crafted packets when ALG is enabled causes a transit traffic Denial of Service — Junos OS 7.5 High 2024-04-12
CVE-2023-52558 OpenBSD 7.4 and 7.3 m_split() network buffer kernel crash — OpenBSD 7.5 - 2024-03-01
CVE-2023-52557 OpenBSD 7.3 invalid l2tp message npppd crash — OpenBSD 7.5 - 2024-03-01
CVE-2023-50736 A vulnerability has been identified in the PostScript interpreter in various Lexmark devices. — various 9.0 Critical 2024-02-28
CVE-2024-23606 Biosig Project libbiosig 安全漏洞 — libbiosig 9.8 Critical 2024-02-20
CVE-2024-23805 F5 Application Visibility and Reporting module and BIG-IP Advanced WAF/ASM vulnerability — BIG-IP 7.5 High 2024-02-14
CVE-2023-6780 Glibc: integer overflow in __vsyslog_internal() — glibc 5.3 Medium 2024-01-31
CVE-2024-23622 IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow — eFilm Workstation 10.0 Critical 2024-01-25
CVE-2024-23621 IBM Merge Healthcare eFilm Workstation License Server Buffer Overflow — eFilm Workstation 10.0 Critical 2024-01-25
CVE-2023-30575 Apache Guacamole: Incorrect calculation of Guacamole protocol element lengths — Apache Guacamole 6.5 Medium 2023-06-07
CVE-2023-24819 RIOT-OS vulnerable to Buffer Overflow during IPHC receive — RIOT 9.8 Critical 2023-04-24
CVE-2022-25731 Incorrect Calculation of Buffer Size in MODEM — Snapdragon 7.5 High 2023-04-04
CVE-2023-1175 Incorrect Calculation of Buffer Size in vim/vim — vim/vim 6.6 - 2023-03-04
CVE-2023-0568 Array overrun in common path resolve code — PHP 7.5 High 2023-02-16
CVE-2022-4378 Linux kernel 缓冲区错误漏洞 — kernel 7.8 - 2023-01-05

Vulnerabilities classified as CWE-131 (缓冲区大小计算不正确) represent 96 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.