CWE-120
4,202 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,202)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51. |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9....Show more |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. |
A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserializ...Show more |
1Documalis 2Free Pdf Editor Free Pdf ScannerJun 17, 2026 Aug 12, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to tr...Show more |
1Hichip 1Shenzhen Hichip Vision Technology Firmware Jun 17, 2026 Aug 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerabi...Show more |
1Passmark 3Burnintest OsforensicsPerformancetestJun 17, 2026 Aug 7, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking it...Show more |
7Apache CanonicalDebian+4 more13Clustered Data Ontap Communications Element ManagerCommunications Session Report Manager+10 moreJun 17, 2026 Aug 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload. |
4Debian GnuOpensuse+1 more4Debian Linux Grub2Leap+1 moreJun 17, 2026 Jul 30, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an u...Show more |
1Qualcomm 47Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+44 moreJun 17, 2026 Jul 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdra...Show more |
1Qualcomm 48Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+45 moreJun 17, 2026 Jul 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industr...Show more |
1Qualcomm 28Apq8053 Firmware Mdm9206 FirmwareMdm9207c Firmware+25 moreJun 17, 2026 Jul 30, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,...Show more |
IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buff...Show more |
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image. |
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability....Show more |
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued...Show more |
1Siemens 1Logo! 8 Bm Firmware Jun 17, 2026 Jul 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerabili...Show more |