CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 35 of 87
- CVE-2022-32527CRITICALCVSS 9.8EG 9.82023-01-30
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Aff…
- CVE-2022-32529CRITICALCVSS 9.8EG 9.82023-01-30
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Aff…
- CVE-2022-32548CRITICALCVSS 10.0EG 10.02022-08-29
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
- CVE-2022-32788CRITICALCVSS 9.8EG 9.82022-09-20
A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.
- CVE-2022-32941CRITICALCVSS 9.8EG 9.82022-11-01
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code…
- CVE-2022-32981HIGHCVSS 7.8EG 7.82022-06-10
An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.
- CVE-2022-33213HIGHCVSS 7.5EG 8.82023-03-10
Memory corruption in modem due to buffer overflow while processing a PPP packet
- CVE-2022-33217HIGHCVSS 7.8EG 7.82022-10-19
Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile
- CVE-2022-33224MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
- CVE-2022-33226MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.
- CVE-2022-33230MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host
- CVE-2022-33232CRITICALCVSS 9.3EG 9.32023-02-12
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
- CVE-2022-33259CRITICALCVSS 9.8EG 9.82023-04-13
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
- CVE-2022-33276HIGHCVSS 8.4EG 8.42023-01-09
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
- CVE-2022-33277HIGHCVSS 8.4EG 8.42023-02-12
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
- CVE-2022-33278HIGHCVSS 7.8EG 7.82023-03-10
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
- CVE-2022-33288CRITICALCVSS 9.3EG 9.32023-04-13
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
- CVE-2022-34740MEDIUMCVSS 6.5EG 6.52022-07-12
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
- CVE-2022-34741MEDIUMCVSS 6.5EG 6.52022-07-12
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
- CVE-2022-34756HIGHCVSS 8.8EG 9.82022-07-13
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)
- CVE-2022-34823CRITICALCVSS 9.8EG 9.82022-11-08
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earli…
- CVE-2022-34886HIGHCVSS 8.8EG 8.82023-10-27
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.
- CVE-2022-34973HIGHCVSS 7.5EG 7.52022-08-03
D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.
- CVE-2022-34998HIGHCVSS 7.8EG 7.82022-08-16
JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl.
- CVE-2022-35003HIGHCVSS 7.8EG 7.82022-08-16
JPEGDEC commit be4843c was discovered to contain a global buffer overflow via ucDitherBuffer at /src/jpeg.inl.
- CVE-2022-35011HIGHCVSS 8.8EG 8.82022-08-16
PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c.
- CVE-2022-35021MEDIUMCVSS 6.5EG 6.52022-09-22
OTFCC commit 617837b was discovered to contain a global buffer overflow via /release-x64/otfccdump+0x718693.
- CVE-2022-35161CRITICALCVSS 9.8EG 9.82022-08-03
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
- CVE-2022-35192HIGHCVSS 7.5EG 7.52022-08-26
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.
- CVE-2022-3550MEDIUMCVSS 5.5EG 9.82022-10-17
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix …
- CVE-2022-35927HIGHCVSS 8.1EG 8.12022-08-04
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DODAG Information Option (DIO) control message can contain a …
- CVE-2022-35928HIGHCVSS 8.4EG 8.42022-08-03
AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and having the version number 3.11 has a vulnerability with respect to reading user-provided passwords and confirmations v…
- CVE-2022-36279HIGHCVSS 8.8EG 8.82023-01-26
A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP reque…
- CVE-2022-3628MEDIUMCVSS 6.6EG 6.62023-01-12
A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges.
- CVE-2022-36280MEDIUMCVSS 6.3EG 6.32022-09-09
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a…
- CVE-2022-36293HIGHCVSS 7.2EG 7.22022-08-16
Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified vectors.
- CVE-2022-36330LOWCVSS 1.9EG 1.92023-05-10
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would requi…
- CVE-2022-36361CRITICALCVSS 9.8EG 9.82022-10-11
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versi…
- CVE-2022-36525CRITICALCVSS 9.8EG 9.82022-08-15
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.
- CVE-2022-36584CRITICALCVSS 9.8EG 9.82022-09-06
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.
- CVE-2022-36585CRITICALCVSS 9.8EG 9.82022-09-07
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.
- CVE-2022-36586CRITICALCVSS 9.8EG 9.82022-09-08
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.
- CVE-2022-36587CRITICALCVSS 9.8EG 9.82022-09-07
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.
- CVE-2022-36588CRITICALCVSS 9.8EG 9.82022-09-08
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.
- CVE-2022-36647MEDIUMCVSS 5.5EG 5.52022-09-02
PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at source/common/header.cc:269.
- CVE-2022-37020MEDIUMCVSS 6.8EG 6.82024-06-10
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
- CVE-2022-37055CRITICALCVSS 9.8EG 9.8⚠ KEV2022-08-28
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
- CVE-2022-37134CRITICALCVSS 9.8EG 9.82022-08-22
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, r…
- CVE-2022-3742MEDIUMCVSS 6.7EG 6.72023-08-23
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
- CVE-2022-37434CRITICALCVSS 9.8EG 9.82022-08-05
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affe…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →