CWE-120
4,417 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password...Show more |
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi. The manipulation of the argum...Show more |
1Totolink 2T10 Firmware T8 FirmwareJun 17, 2026 Sep 8, 2024 8.7 HIGH· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setStaticDhcpRules of the file /cgi-bin/...Show more |
1Totolink 2T10 Firmware T8 FirmwareJun 17, 2026 Sep 8, 2024 8.7 HIGH· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The m...Show more |
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc...Show more |
1Totolink 2T10 Firmware T8 FirmwareJun 17, 2026 Sep 8, 2024 8.7 HIGH· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manip...Show more |
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network...Show more |
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have alr...Show more |
Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states th...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCA...Show more |
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. |
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. |
A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from...Show more |
1Zyxel 50Ax7501 B0 Firmware Ax7501 B1 FirmwareDx3300 T0 Firmware+47 moreJun 17, 2026 Sep 3, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafte...Show more |
1Qualcomm 32Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+29 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. |
1Qualcomm 197205 Mobile Firmware 215 Mobile FirmwareApq8017 Firmware+194 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when user provides data for FM HCI command control operations. |
1Qualcomm 196205 Firmware 215 FirmwareApq8017 Firmware+193 moreJun 17, 2026 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when Alternative Frequency offset value is set to 255. |
xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a speci...Show more |