← Back
CWE-120

4,439 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,439)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
4Opcenter Quality
Simatic Pcs NeoSinumerik Integrate Runmyhmi /automotive+1 more
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally In...Show more
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash.Show less
1Afichet
1Openexr Viewer
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via...Show more
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.2.2534 build 20230927 and later Show less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Dec 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via...Show more
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.2.2534 build 20230927 and later Show less
1Struktur
1Libde265
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.
1Strongswan
1Strongswan
Jun 17, 2026
Dec 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. A...Show more
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.Show less
1Qualcomm
90Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+87 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
1Qualcomm
117Apq5053 Aa Firmware
Ar8035 FirmwareCsra6620 Firmware+114 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Core while processing RX intent request.
1Qualcomm
115Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+112 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption in WLAN Host while processing RRM beacon on the AP.
1Qualcomm
115Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+112 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
1Qualcomm
718098 Firmware
8998 FirmwareAqt1000 Firmware+68 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while sending SMS from AP firmware.
1Qualcomm
276315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+273 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
1Qualcomm
44Ar8035 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+41 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
1Qualcomm
34Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareQam8295p Firmware+31 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
1Qualcomm
274315 5g Iot Modem Firmware
9205 Lte Modem FirmwareApq8017 Firmware+271 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in SPS Application while exporting public key in sorter TA.
1Cxong
1Tinydir
Jun 17, 2026
Dec 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929788; Issue ID: ALPS07929788.Show less
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...Show more
In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08000473; Issue ID: ALPS08000473.Show less
1Szlbt
1Lbt T300 T310 Firmware
Jun 17, 2026
Nov 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
KeepserverexKepserver Enterprise+5 more
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.