CWE-120
4,412 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Jul 5, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via...Show more |
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object point...Show more |
Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified...Show more |
1Microsoft 4Exchange Server Windows 2000Windows Server 2003+1 moreApr 16, 2026 Oct 13, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a l...Show more |
2Debian Www Sql Project2Debian Linux Www SqlApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql. |
1Microsoft 3Interix Windows 2000Windows NtApr 16, 2026 Aug 6, 2004 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow. |
Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS. |
Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension. |
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. |
Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary...Show more |
1Wireless Tools Project 1Wireless Tools Apr 16, 2026 Dec 15, 2003 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable. |
1Terascript 1Wintango Application Server Apr 16, 2026 Aug 27, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference. |
3Debian Falconseye ProjectNethack3Debian Linux FalconseyeNethackApr 16, 2026 Jun 9, 2003 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. |
7Gentoo HpNetbsd+4 more9Alphaserver Sc BsdosHp Ux+6 moreApr 16, 2026 Mar 7, 2003 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of...Show more |
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, who...Show more |
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lo...Show more |
6Debian FreebsdGnu+3 more6Debian Linux FreebsdLinux+3 moreJul 23, 2026 Mar 8, 2002 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling." |
9Debian FreebsdIbm+6 more11Aix Debian LinuxFreebsd+8 moreApr 16, 2026 Aug 14, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more |
Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_e...Show more |