← Back
CWE-120

4,227 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,227)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Extremenetworks
1Iq Engine
Jun 17, 2026
Oct 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
1Tenda
1Ac6 Firmware
Jun 17, 2026
Oct 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
1Qualcomm
143Apq5053 Aa Firmware
Ar8035 FirmwareCsra6620 Firmware+140 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while invoking callback function of AFE from ADSP.
1Qualcomm
157Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+154 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
1Qualcomm
9Qca6574au Firmware
Qca6696 FirmwareSa6145p Firmware+6 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).
1Optipng Project
1Optipng
Jun 17, 2026
Oct 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.
1Linux
1Linux Kernel
Jun 17, 2026
Sep 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This...Show more
An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.Show less
1Zyxel
1Pmg2005 T20b Firmware
Jun 17, 2026
Sep 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauthenticated attacker to cause a denial of service condition via a crafted...Show more
** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauthenticated attacker to cause a denial of service condition via a crafted uid.Show less
1Zephyrproject
1Zephyr
Jun 17, 2026
Sep 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
1Zephyrproject
1Zephyr
Jun 17, 2026
Sep 27, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
1Zephyrproject
1Zephyr
Jun 17, 2026
Sep 27, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
1Zephyrproject
1Zephyr
Jun 17, 2026
Sep 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
1Maxiguvenlik
1General Device Manager
Jun 17, 2026
Sep 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
1Qnap
1Multimedia Console
Jun 17, 2026
Sep 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We hav...Show more
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 ) and later Multimedia Console 1.4.7 ( 2023/03/20 ) and later Show less
1Qnap
1Qts
Jun 17, 2026
Sep 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have...Show more
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2441 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later Show less
1Jerryscript
1Jerryscript
Jun 17, 2026
Sep 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.
1Tenda
1Ac10 Firmware
Jun 17, 2026
Sep 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.