← Back
CWE-120

4,440 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,440)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foxit
1Pdf Reader
Jul 9, 2026
Aug 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
1Matthiaswandel
1Jhead
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
1Rockcarry
1Ffjpeg
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.
1Mdadm Project
1Mdadm
Jun 17, 2026
Aug 11, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access.
1Ezsoftmagic
1Mp3 Audio Converter
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
1Samsung
5S3nrn4v Firmware
S3nrn82 FirmwareS3nsen4 Firmware+2 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.
1Qualcomm
1Qcn7606 Firmware
Jun 17, 2026
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption in QESL while processing payload from external ESL device to firmware.
1Qualcomm
65Apq8096au Firmware
Aqt1000 FirmwareMdm9628 Firmware+62 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
1Clusterlabs
1Libqb
Jun 17, 2026
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
1Netgear
3Jwnr2000v2 Firmware
Xavn2001v2 FirmwareXwn5001 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function.
1Netgear
1Ex6200 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear EX6200 v1.0.3.94 was discovered to contain a buffer overflow via the wla_temp_ssid parameter at acosNvramConfig_set.
1Netgear
3Dc112a Firmware
Ex6200 FirmwareR6300v2 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi.
1Netgear
1Dgn3500 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.
1Netgear
3Jwnr2000v2 Firmware
Xavn2001v2 FirmwareXwn5001 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function.
1Netgear
1Dg834gv5 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi.
1Netgear
1R6900p Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi.
1Netgear
1Xr300 Firmware
Jun 17, 2026
Aug 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.
1Cloudflare
1Odoh Rs
Jun 17, 2026
Aug 3, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clie...Show more
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients and enables an attacker with knowledge of this vulnerability to craft and send specially designed encrypted queries to targeted ODOH servers running with odoh-rs. Upon successful exploitation, the server will crash abruptly, disrupting its normal operation and rendering the service temporarily unavailable. Show less
1Mitsubishielectric
21C80 Firmware
E70 FirmwareE80 Firmware+18 more
Jun 17, 2026
Aug 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code...Show more
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.Show less
1Broadcom
1Brocade Fabric Operating System
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service...Show more
A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.Show less