Using a tainted value to write to an object using a formatted input or output function [taintformatio] Tainted strings are passed to a string copying function [taintstrcpy]
CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-120, Buffer Copy without Checking Size of Input ("Classic Buffer Overflow") CWE-193, Off-by-one Error