CWE-120
4,430 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when reading images in EXR format. |
In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf w...Show more |
2Debian Linux2Debian Linux Linux KernelAug 4, 2026 Mar 18, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before copying from the scomp_scratch->dst to avoid req->dst b...Show more |
1Totolink 2A7000r Firmware X5000r FirmwareJun 17, 2026 Mar 16, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field. |
In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the co...Show more |
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be trigg...Show more |
1Siemens 9Cerberus Pro En Engineering Tool Cerberus Pro En Fire Panel Fc72xCerberus Pro En X200 Cloud Distribution+6 moreJun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5),...Show more |
In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is no...Show more |
In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interacti...Show more |
1Razormist 1Tourist Reservation System Jun 17, 2026 Mar 9, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file System.cpp. The manipulation of the argument...Show more |
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17....Show more |
Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components. |
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. |
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the ne...Show more |
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privileg...Show more |
1Qualcomm 136Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+133 moreJun 17, 2026 Mar 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption while parsing qcp clip with invalid chunk data size. |
1Qualcomm 29Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+26 moreJun 17, 2026 Mar 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing the IOCTL FM HCI WRITE request. |
1Qualcomm 42Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+39 moreJun 17, 2026 Mar 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake. |
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST re...Show more |
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop proce...Show more |