CWE-120
4,473 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,473)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 29Scalance X200 4p Irt Firmware Scalance X201 3p Irt FirmwareScalance X201 3p Irt Pro Firmware+26 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5...Show more |
1Gps Sdr Sim Project 1Gps Sdr Sim Jun 17, 2026 Jun 30, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution. |
3Debian LinuxRedhat4Debian Linux Enterprise LinuxLinux Kernel+1 moreJun 17, 2026 Jun 30, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly t...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy without checking the size of the service, resulting in a denial-of-service c...Show more |
1Realtek 7Rtl8152b Firmware Rtl8153 FirmwareRtl8153b Firmware+4 moreJun 17, 2026 Jun 20, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services. |
1Mitel 2Mivoice Business Mivoice Business ExpressJun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interfac...Show more |
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection,...Show more |
1Ok File Formats Project 1Ok File Formats Jun 17, 2026 Jun 15, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB. |
1Qualcomm 155Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+152 moreJun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 memory corruption in video due to buffer overflow while parsing mkv clip with no codechecker in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon...Show more |
1Qualcomm 153Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+150 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption due to possible buffer overflow while parsing DSF header with corrupted channel count in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Qualcomm 45Ar8035 Firmware Ipq5010 FirmwareIpq5018 Firmware+42 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industria...Show more |
1Qualcomm 2Sa8540p Firmware Sa9000p FirmwareJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto |
1Qualcomm 176Apq8009w Firmware Apq8017 FirmwareApq8064au Firmware+173 moreJun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrago...Show more |
1Qualcomm 68Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+65 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 73Aqt1000 Firmware Ar8035 FirmwareQca6390 Firmware+70 moreJun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electr...Show more |
1Qualcomm 79Apq8097 Firmware Apq8098 FirmwareIpq6000 Firmware+76 moreJun 17, 2026 Jun 14, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon...Show more |
There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation. |
An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers. |
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Jun 9, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack b...Show more |
Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d "array[_0][0][array][_0][0][...Show more |