CAPEC-24: Filter Failure through Buffer Overflow
In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
Severity
High
Likelihood
High
15
/ 100
low-risk
Active Threat
12/50 · Low
Exploit Availability
3/50 · Minimal