CWE-120
4,319 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,319)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Sep 15, 2010 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Applicati...Show more |
3Avaya LinuxVmware9Aura Communication Manager Aura Presence ServicesAura Session Manager+6 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash)...Show more |
3Apple CanonicalFreetype5Freetype Iphone OsMac Os X+2 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrar...Show more |
2Canonical Freetype2Freetype Ubuntu LinuxApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file. |
3Canonical DebianFreetype3Debian Linux FreetypeUbuntu LinuxApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file. |
4Apple CanonicalDebian+1 more4Debian Linux FreetypeMac Os X+1 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted L...Show more |
10Apple CanonicalDebian+7 more17Chrome Debian LinuxFedora+14 moreApr 29, 2026 Jun 30, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data r...Show more |
Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during exp...Show more |
Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the...Show more |
1Microsoft 26.net Framework Excel ViewerExpression Web+23 moreApr 23, 2026 Oct 14, 2009 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer,...Show more |
1Microsoft 1Internet Information Server Apr 23, 2026 Aug 31, 2009 N/A· v4 N/A· v3 9.0 HIGH· v2 Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards,...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Debuginfo+5 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments. |
1Filezilla Project 1Filezilla Server Apr 23, 2026 Mar 12, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets. |
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line. |
4Canonical DebianLinux+1 more5Debian Linux Linux KernelSuse Linux Enterprise Desktop+2 moreApr 23, 2026 Aug 12, 2008 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allow...Show more |
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown im...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Aug 1, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect m...Show more |
1Redhat 2Directory Server Fedora Directory ServerApr 23, 2026 May 12, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LD...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less...Show more |
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be su...Show more |