← Back
CWE-120

4,476 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
1Ua Lite Firmware
Jun 17, 2026
Apr 1, 2022
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devi...Show more
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.Show less
1Moxa
4Nport Iaw5150a 12i/o Firmware
Nport Iaw5150a 6i/o FirmwareNport Iaw5250a 12i/o Firmware+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.
1Qualcomm
3Qca6574au Firmware
Qca6696 FirmwareSa8155p Firmware
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto
1Qualcomm
77Ar8035 Firmware
Fsm10055 FirmwareFsm10056 Firmware+74 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, S...Show more
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon WearablesShow less
1Bosch
68Autodome 7000 Firmware
Autodome Ip 4000 Hd FirmwareAutodome Ip 4000i Firmware+65 more
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with admin...Show more
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.Show less
1Bosch
68Autodome 7000 Firmware
Autodome Ip 4000 Hd FirmwareAutodome Ip 4000i Firmware+65 more
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with admi...Show more
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.Show less
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
1Xiongmaitech
10Ahb80n16t Gs Firmware
Ahb80n32f4 Lme FirmwareAhb80x04 R Mh V3 Firmware+7 more
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to caus...Show more
A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request.Show less
1Netu
1Mex01 Firmware
Jun 17, 2026
Mar 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this vulnerability by using the property that the target program copies parameter values to memory throu...Show more
An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this vulnerability by using the property that the target program copies parameter values to memory through the strcpy() function.Show less
1Openbsd
1Openbsd
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitati...Show more
engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.Show less
1Totolink
1T10 V2 Firmware
Jun 17, 2026
Mar 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in the HTTP request process.
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Mar 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary...Show more
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Nxp
6Lpc55s66jbd100 Firmware
Lpc55s66jbd64 FirmwareLpc55s66jev98 Firmware+3 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This ca...Show more
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.Show less
1Tendacn
1Ac10 Firmware
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.
1Tendacn
1Ac10 Firmware
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
1Irfanview
1Irfanview
Jul 9, 2026
Mar 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.
1Asus
1Rt Ac68u Firmware
Jul 9, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).