CWE-120
4,412 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or bru...Show more |
Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. |
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument. |
3Cygnus Network Security Project Kerbnet ProjectMit4Cygnus Network Security KerberosKerberos 5+1 moreApr 16, 2026 Jun 9, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function. |
3Cygnus Network Security Project Kerbnet ProjectMit4Cygnus Network Security KerberosKerberos 5+1 moreApr 16, 2026 Jun 9, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function. |
3Cygnus Network Security Project Kerbnet ProjectMit4Cygnus Network Security KerberosKerberos 5+1 moreApr 16, 2026 Jun 9, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function. |
Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine. |
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long...Show more |
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
2Ibm Microsoft2Exchange Server Lotus Domino Mail ServerApr 16, 2026 Jan 1, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |
7Bsdi Data GeneralDebian+4 more8Aix Bsd OsDebian Linux+5 moreApr 16, 2026 Apr 26, 1997 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 Buffer overflow in xlock program allows local users to execute commands as root. |
10Bsdi DebianDigital+7 more10Aix Bsd OsDebian Linux+7 moreApr 16, 2026 Feb 6, 1997 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow of rlogin program using TERM environmental variable. |