← Back
CWE-120

4,202 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,202)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Serenityos
1Serenityos
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
1Riot Os
1Riot
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
1Riot Os
1Riot
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information.
1Riot Os
1Riot
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.
1Riot Os
1Riot
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information.
1Riot Os
1Riot
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.
1Contiki Ng
1Contiki Ng.
Jun 17, 2026
Jun 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-sock...Show more
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a packet with a data offset that is unvalidated. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.Show less
1Contiki Ng
1Contiki Ng.
Jun 17, 2026
Jun 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implem...Show more
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implementations in source-routing mode. The problem has been patched in Contiki-NG 4.5. Users can apply the patch for this vulnerability out-of-band as a workaround.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Jun 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv v...Show more
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.Show less
1Accusoft
1Imagegear
Jun 17, 2026
Jun 11, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious i...Show more
A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.
2Fedoraproject
Xscreensaver Project
2Fedora
Xscreensaver
Jun 17, 2026
Jun 10, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism...Show more
XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.Show less
1Intel
1Baseboard Management Controller Firmware
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjac...Show more
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.Show less
1Intel
1Efi Bios 7215
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Buffer overflow in the BMC firmware for Intel(R) Server BoardM10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable an escalation of privilege via adjacent access.
1Qualcomm
177Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+174 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT...Show more
Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Sharp Nec Displays
34C431 Firmware
C501 FirmwareC551 Firmware+31 more
Jun 17, 2026
Jun 7, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1....Show more
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker a buffer overflow and to execute remote code by sending long parameters that contains specific characters in http request.Show less
2Debian
F5
2Debian Linux
Nginx
Dec 5, 2025
Jun 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), wh...Show more
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.Show less
2Aomedia
Fedoraproject
2Aomedia
Fedora
Jun 17, 2026
Jun 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
2Libtpms Project
Redhat
2Enterprise Linux
Libtpms
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat f...Show more
A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.Show less
1Apple
1Files
Nov 21, 2024
Jun 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.