CWE-120
4,202 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,202)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJun 17, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJun 17, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe. |
1Clickhouse Driver Project 1Clickhouse Driver Jun 17, 2026 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow. |
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) software. The Bluetooth UART driver has a buffer overflow. The Samsung ID is SVE-2020-18731 (January 2021). |
4Debian FedoraprojectLinux+1 more5Cloud Backup Debian LinuxFedora+2 moreJun 17, 2026 Jan 5, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. |
An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut. |
1Netgear 69Cbr40 Firmware D6220 FirmwareD6400 Firmware+66 moreJun 17, 2026 Dec 30, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D8500 before 1.0.3.50,...Show more |
1Netgear 77Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+74 moreJun 17, 2026 Dec 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10,...Show more |
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user. |
1Netgear 26D3600 Firmware D6000 FirmwareD6200 Firmware+23 moreJun 17, 2026 Dec 30, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.36, D7000 before 1.0.1.70, EX6200v2 before 1.0.1.78, EX70...Show more |
NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user. |
1Struct2json Project 1Struct2json Jun 17, 2026 Dec 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT. |
The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far. |
1Miniweb Http Server Project 1Miniweb Http Server Jun 17, 2026 Dec 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request. |
2Oracle Wireshark2Wireshark Zfs Storage Appliance KitJun 17, 2026 Dec 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file |
An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can u...Show more |
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated against the requested size. The parameter siz...Show more |
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_read whose return size was not validated against the requrested size. The parameter size i...Show more |
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_inet_pton using an attacker controlled klinux_addr_buffer parameter. The parameter size is...Show more |
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvmsg using an attacker controlled result parameter. The parameter size is unchecked all...Show more |