CWE-120
4,201 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,201)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s,...Show more |
1Qualcomm 8Nicobar Firmware Sdm670 FirmwareSdm710 Firmware+5 moreJun 17, 2026 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicobar, SDM670, SDM710, S...Show more |
1Qualcomm 47Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+44 moreJun 17, 2026 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read into the table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C...Show more |
1Qualcomm 43Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+40 moreJun 17, 2026 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Qualcomm 8Mdm9607 Firmware Msm8909w FirmwareMsm8917 Firmware+5 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial...Show more |
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. |
4Compal NetgearSagemcom+1 more77284e Firmware 7486e FirmwareC6250emr Firmware+4 moreJun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerabil...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within t...Show more |
In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user input based on the format specifier string...Show more |
2Opencv Oracle4Application Testing Suite Big Data Spatial And GraphEnterprise Manager Base Platform+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple h...Show more |
2Opencv Oracle4Application Testing Suite Big Data Spatial And GraphEnterprise Manager Base Platform+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions a...Show more |
1Huawei 26Ar120 S Firmware Ar1200 S FirmwareAr1200 Firmware+23 moreJun 17, 2026 Jan 3, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters i...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. |
5Canonical DebianEglibc+2 more5Debian Linux EglibcFedora+2 moreNov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. |
1Static Http Server Project 1Static Http Server Nov 21, 2024 Dec 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Static HTTP Server 1.0 has a Local Overflow |
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attack...Show more |
Huawei smart phones with earlier versions than ELLE-AL00B 9.1.0.222(C00E220R2P1) have a buffer overflow vulnerability. An attacker may intercept and tamper with the packet in the local area network (LAN) to exploit this...Show more |
3Fedoraproject Lout ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. |