CWE-120
4,478 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,478)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service. |
Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or exe...Show more |
Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbi...Show more |
1Hp 2Integrated Lights Out 4 Integrated Lights Out 5Jun 17, 2026 May 25, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 26...Show more |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 May 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service |
2Hp Samsung382Clp 360 Ss062a Clp 365 Ss066aClp 365 Ss067a+379 moreJun 17, 2026 May 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege. |
2Opensuse Oracle2Communications Cloud Native Core Policy LibsolvJun 17, 2026 May 18, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which co...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in Eigen implementation of `tf.raw_ops.BandedTriangularSolve`. The implementation(https://github.com/t...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter`. This is because the implementation(https://github.com/tensorflow/ten...Show more |
TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_ops.Conv3DBackprop*` operations can result in heap buffer overflows. This is because the implementati...Show more |
TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseTensor`(https://www.tensorflow.org/api_docs/python/tf/sparse/SparseTenso...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 May 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integr...Show more |
2C Ares Fedoraproject2C Ares FedoraJun 17, 2026 May 13, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib....Show more |
1Qualcomm 404Apq8096au Firmware Aqt1000 FirmwareAr8031 Firmware+401 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consume...Show more |
1Google 1Cloud Iot Device Sdk For Embedded C Jun 17, 2026 May 4, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowin...Show more |