CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 48 of 87
- CVE-2023-42278HIGHCVSS 7.5EG 7.52023-09-08
hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().
- CVE-2023-42299CRITICALCVSS 9.8EG 9.82023-11-02
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
- CVE-2023-42320CRITICALCVSS 9.8EG 9.82023-09-18
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.
- CVE-2023-4257CRITICALCVSS 9.8EG 9.82023-10-13
Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
- CVE-2023-4259HIGHCVSS 8.8EG 8.82023-09-26
Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
- CVE-2023-4260CRITICALCVSS 10.0EG 10.02023-09-27
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
- CVE-2023-4263HIGHCVSS 8.8EG 8.82023-10-13
Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver
- CVE-2023-4264CRITICALCVSS 9.6EG 9.62023-09-27
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
- CVE-2023-4265MEDIUMCVSS 6.8EG 6.82023-08-12
Potential buffer overflow vulnerabilities in the following locations: https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/…
- CVE-2023-42757MEDIUMCVSS 4.2EG 4.22024-05-07
Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This …
- CVE-2023-42799HIGHCVSS 8.8EG 8.82023-12-14
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsaf…
- CVE-2023-42800HIGHCVSS 8.8EG 8.82023-12-14
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsaf…
- CVE-2023-42801HIGHCVSS 7.6EG 7.62023-12-14
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming serve…
- CVE-2023-43010HIGHCVSS 8.8EG 8.82026-03-12
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web conten…
- CVE-2023-43131CRITICALCVSS 9.8EG 9.82023-09-25
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
- CVE-2023-43250HIGHCVSS 7.8EG 7.82023-10-18
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
- CVE-2023-43314HIGHCVSS 7.5EG 7.52023-09-27
** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauthenticated attacker to cause a denial of service condition via a crafted uid.
- CVE-2023-43504CRITICALCVSS 9.8EG 9.82023-11-14
A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This cou…
- CVE-2023-43515MEDIUMCVSS 6.6EG 6.62024-04-01
Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.
- CVE-2023-43519HIGHCVSS 7.3EG 7.32024-02-06
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
- CVE-2023-43524MEDIUMCVSS 6.7EG 6.72024-05-06
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
- CVE-2023-43525MEDIUMCVSS 6.7EG 6.72024-05-06
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
- CVE-2023-43526MEDIUMCVSS 6.7EG 6.72024-05-06
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
- CVE-2023-43538CRITICALCVSS 9.3EG 9.32024-06-03
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
- CVE-2023-43540HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption while processing the IOCTL FM HCI WRITE request.
- CVE-2023-43542HIGHCVSS 7.8EG 7.82024-06-03
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- CVE-2023-43548HIGHCVSS 7.3EG 7.32024-03-04
Memory corruption while parsing qcp clip with invalid chunk data size.
- CVE-2023-43556CRITICALCVSS 9.3EG 9.32024-06-03
Memory corruption in Hypervisor when platform information mentioned is not aligned.
- CVE-2023-43567MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43569MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43571MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43573MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43575MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43576MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43577MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43578MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43579MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43580MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43581MEDIUMCVSS 6.7EG 6.72023-11-08
A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2023-43615HIGHCVSS 7.5EG 7.52023-10-07
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
- CVE-2023-43815HIGHCVSS 7.1EG 7.12024-01-18
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to o…
- CVE-2023-43816MEDIUMCVSS 6.3EG 6.32024-01-18
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a…
- CVE-2023-43817HIGHCVSS 7.5EG 7.52024-01-18
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially c…
- CVE-2023-43818HIGHCVSS 8.8EG 8.82024-01-18
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.
- CVE-2023-43819HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to ope…
- CVE-2023-43820HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user…
- CVE-2023-43821HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to…
- CVE-2023-43822HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to o…
- CVE-2023-43823HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a s…
- CVE-2023-43824HIGHCVSS 8.8EG 8.82024-01-18
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open …
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →