CWE-120
4,443 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. |
1Zyxel 4Lte7480 M804 Firmware Lte7490 M904 FirmwareNebula Nr7101 Firmware+1 moreJun 17, 2026 Jun 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could allow a remote authenticated attacker to cause denial of service (DoS) conditions by sending a craf...Show more |
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files
This issue affects libeconf: before 0.5.2.
|
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files.
This issue affects libeconf: before 0.5.2. |
1Gallagher 1Controller 6000 Firmware Jun 17, 2026 Jun 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.2302...Show more |
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthentica...Show more |
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. |
1Zyxel 23Atp100 Firmware Atp100w FirmwareAtp200 Firmware+20 moreJun 17, 2026 May 24, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions...Show more |
1Zyxel 23Atp100 Firmware Atp100w FirmwareAtp200 Firmware+20 moreJun 17, 2026 May 24, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions...Show more |
1Mitsubishielectric 39Melsec Iq Fx5u 32mr/ds Firmware Melsec Iq Fx5u 32mr/dss FirmwareMelsec Iq Fx5u 32mr/es Firmware+36 moreJun 17, 2026 May 24, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated at...Show more |
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the ex...Show more |
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious applic...Show more |
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application...Show more |
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call t...Show more |