← Back
CWE-120

4,439 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,439)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
16Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+13 more
Jun 17, 2026
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Aut...Show more
An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.Show less
1Gpac
1Gpac
Jun 17, 2026
Nov 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.
1Qualcomm
151Apq5053 Aa Firmware
Aqt1000 FirmwareAr8035 Firmware+148 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Audio while invoking callback function in driver from ADSP.
1Qualcomm
128Ar8035 Firmware
Csr8811 FirmwareImmersive Home 214 Platform Firmware+125 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
1Qualcomm
164Apq5053 Aa Firmware
Apq8009 FirmwareApq8017 Firmware+161 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
1Qualcomm
83Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+80 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing audio effects.
1Synology
1Ssl Vpn Client
Jun 17, 2026
Nov 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified v...Show more
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.Show less
1Redislabs
1Redisgraph
Jun 17, 2026
Nov 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.
2Redhat
Squid Cache
10Enterprise Linux
Enterprise Linux EusEnterprise Linux For Arm 64+7 more
Aug 7, 2026
Nov 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication...Show more
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.Show less
1Openimageio
1Openimageio
Jun 17, 2026
Nov 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
2Libtiff
Redhat
2Enterprise Linux
Libtiff
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.
1Moxa
8Edr 810 2gsfp T Firmware
Edr 810 2gsfp FirmwareEdr 810 Vpn 2gsfp T Firmware+5 more
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, p...Show more
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot. Show less
1Dronecode
1Px4 Drone Autopilot
Jun 17, 2026
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value...Show more
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading unexpected drone behavior. Malicious applications can exploit the vulnerability even if device sensor malfunction does not occur. Up to the maximum value of an `unsigned int`, bytes sized data can be written to the heap memory area. As of time of publication, no fixed version is available.Show less
1Dreamsecurity
1Magicline 4.0
Jun 17, 2026
Oct 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.
1Xnview
1Xnview
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
1Memcached
1Memcached
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
1Lenovo
3G263dns Firmware
Gm265dn FirmwareGm266dns Firmware
Jun 17, 2026
Oct 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack...Show more
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.Show less
1Abus
47Tvip 10000 Firmware
Tvip 10001 FirmwareTvip 10005 Firmware+44 more
Nov 21, 2024
Oct 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.
1Zephyrproject
1Zephyr
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
1Zephyrproject
1Zephyr
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c