← Back
CWE-120

4,417 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.
1Tenda
1Ac7 Firmware
Jun 17, 2026
Mar 19, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.
-
-
Jun 17, 2026
Mar 17, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.
1Tendacn
1Ac9 Firmware
Jun 17, 2026
Mar 14, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
1Autodesk
9Advance Steel
AutocadAutocad Architecture+6 more
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the curr...Show more
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Tenda
1Rx3 Firmware
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial...Show more
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.Show less
1Tenda
1Rx3 Firmware
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pac...Show more
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.Show less
1Tenda
1Rx3 Firmware
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVirtualServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted...Show more
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVirtualServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.Show less
1Tenda
1Rx3 Firmware
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...Show more
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.Show less