← Back
CWE-120

4,478 CVEs • Abstraction: Base • Likelihood of Exploit: High

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

JSON object

Loading...

CVEs (4,478)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
2Gs116e Firmware
Jgs516pe Firmware
Jun 17, 2026
Mar 10, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedL...Show more
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.Show less
1Netgear
2Gs116e Firmware
Jgs516pe Firmware
Jun 17, 2026
Mar 10, 2021
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of service attacks.
1Netgear
2Gs116e Firmware
Jgs516pe Firmware
Jun 17, 2026
Mar 10, 2021
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.
1Msi
1Dragon Center
Jun 17, 2026
Mar 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.
1Gigaset
1Dx600a Firmware
Jun 17, 2026
Mar 2, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated...Show more
A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful exploit could allow a local attacker to execute arbitrary code within the context the binary is running in, which is a lower privileged account.Show less
1Qualcomm
202Aqt1000 Firmware
Pm3003a FirmwarePm456 Firmware+199 more
Jun 17, 2026
Feb 22, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Sna...Show more
Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon WearablesShow less
1Qualcomm
505Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+502 more
Jun 17, 2026
Feb 22, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, S...Show more
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and NetworkingShow less
1Intel
1Bmc Firmware
Jun 17, 2026
Feb 19, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.
1Digium
1Asterisk
Jun 17, 2026
Feb 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
5Debian
FedoraprojectIsc+2 more
7500f Firmware
A250 FirmwareBind+4 more
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server...Show more
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. The most likely outcome of a successful exploitation of the vulnerability is a crash of the named process. However, remote code execution, while unproven, is theoretically possible. Affects: BIND 9.5.0 -> 9.11.27, 9.12.0 -> 9.16.11, and versions BIND 9.11.3-S1 -> 9.11.27-S1 and 9.16.8-S1 -> 9.16.11-S1 of BIND Supported Preview Edition. Also release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branchShow less
1Intel
1Ethernet Network Adapter E810 Firmware
Jun 17, 2026
Feb 17, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1Intel
1Ethernet Network Adapter E810 Firmware
Jun 17, 2026
Feb 17, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable a denial of service via local access.
1Intel
1Ethernet Network Adapter E810 Firmware
Jun 17, 2026
Feb 17, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable denial of service via local access.
1F5
2Big Ip Domain Name System
Big Ip Global Traffic Manager
Jun 17, 2026
Feb 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have re...Show more
On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.Show less
1Logitech
1Lan W300n/pgrb Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.8 MEDIUM· v3
7.7 HIGH· v2
Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.
1Adobe
1Photoshop
Jun 17, 2026
Feb 11, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted javascript file. An unauthenticated attacker could leverage this vul...Show more
Adobe Photoshop versions 21.2.4 (and earlier) and 22.1.1 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted javascript file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
2Fedoraproject
Symonics
2Fedora
Libmysofa
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.