CWE-120
4,423 CVEs • Abstraction: Base • Likelihood of Exploit: High
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CVEs (4,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ibm Microsoft2Exchange Server Lotus Domino Mail ServerApr 16, 2026 Jan 1, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |
7Bsdi Data GeneralDebian+4 more8Aix Bsd OsDebian Linux+5 moreApr 16, 2026 Apr 26, 1997 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 Buffer overflow in xlock program allows local users to execute commands as root. |
10Bsdi DebianDigital+7 more10Aix Bsd OsDebian Linux+7 moreApr 16, 2026 Feb 6, 1997 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow of rlogin program using TERM environmental variable. |