CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 52 of 87
- CVE-2024-0816MEDIUMCVSS 5.5EG 5.52024-05-21
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected de…
- CVE-2024-10371MEDIUMCVSS 6.3EG 6.32024-10-25
A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the publi…
- CVE-2024-10467HIGHCVSS 8.8EG 9.82024-10-29
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary co…
- CVE-2024-10559MEDIUMCVSS 5.3EG 5.32024-10-31
A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function Details. The manipulation of the argument passport/name leads to buffer overflow. The atta…
- CVE-2024-10964MEDIUMCVSS 6.3EG 6.32024-11-07
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow…
- CVE-2024-11959HIGHCVSS 8.8EG 8.82024-11-28
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflo…
- CVE-2024-11960HIGHCVSS 8.8EG 8.82024-11-28
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overf…
- CVE-2024-12147MEDIUMCVSS 6.5EG 6.52024-12-04
A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file upgrade_check.cgi of the component HTTP Header Handler. The manipulation o…
- CVE-2024-12178HIGHCVSS 7.8EG 7.82024-12-17
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- CVE-2024-12194HIGHCVSS 7.8EG 7.82024-12-17
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- CVE-2024-12343MEDIUMCVSS 6.5EG 6.52024-12-08
A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewCon…
- CVE-2024-12354MEDIUMCVSS 5.3EG 5.32024-12-09
A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow…
- CVE-2024-12373CRITICALCVSS 9.3EG 9.32024-12-18
A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service.
- CVE-2024-12988HIGHCVSS 7.3EG 7.32024-12-27
A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to…
- CVE-2024-13503CRITICALCVSS 9.5EG 9.52025-01-17
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, R…
- CVE-2024-1755HIGHCVSS 8.8EG 8.82024-04-15
The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-1786HIGHCVSS 7.5EG 7.52024-02-23
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation of the arg…
- CVE-2024-1969HIGHCVSS 8.2EG 8.22024-04-29
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateManager: from 9.7 before 11.2.624095033.
- CVE-2024-20267HIGHCVSS 8.6EG 8.62024-02-29
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traff…
- CVE-2024-20313HIGHCVSS 7.4EG 7.42024-04-24
A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vu…
- CVE-2024-20450CRITICALCVSS 9.8EG 9.82024-08-07
Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands o…
- CVE-2024-20451HIGHCVSS 7.5EG 7.52024-08-07
Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to …
- CVE-2024-20454CRITICALCVSS 9.8EG 9.82024-08-07
Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands o…
- CVE-2024-20723HIGHCVSS 7.8EG 7.82024-02-15
Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that…
- CVE-2024-21274HIGHCVSS 7.5EG 7.52024-10-15
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2024-21463HIGHCVSS 7.3EG 7.32024-04-01
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
- CVE-2024-21464HIGHCVSS 8.4EG 8.42025-01-06
Memory corruption while processing IPA statistics, when there are no active clients registered.
- CVE-2024-21480HIGHCVSS 7.3EG 7.32024-05-06
Memory corruption while playing audio file having large-sized input buffer.
- CVE-2024-21758MEDIUMCVSS 6.4EG 6.42025-01-14
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb …
- CVE-2024-22039CRITICALCVSS 10.0EG 10.02024-03-12
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X20…
- CVE-2024-22419HIGHCVSS 7.3EG 7.32024-01-18
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thus overwrite existing valid data. The root cause is that the…
- CVE-2024-22472HIGHCVSS 8.1EG 8.12024-05-07
A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all versions of Silicon Labs 500 Series SDK prior to v6.85.2 running on Silic…
- CVE-2024-22526MEDIUMCVSS 5.5EG 5.52024-04-12
Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.
- CVE-2024-22749HIGHCVSS 7.8EG 7.82024-01-25
GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577
- CVE-2024-22905HIGHCVSS 7.0EG 7.02024-04-19
Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSerialRxIncoming function.
- CVE-2024-22912HIGHCVSS 7.8EG 7.82024-01-19
A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.
- CVE-2024-22919HIGHCVSS 7.8EG 7.82024-01-19
swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.
- CVE-2024-23077HIGHCVSS 7.5EG 7.52024-04-10
JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the exis…
- CVE-2024-23079MEDIUMCVSS 6.2EG 6.22024-04-08
JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reas…
- CVE-2024-23286HIGHCVSS 7.8EG 9.82024-03-08
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, wa…
- CVE-2024-2331MEDIUMCVSS 6.3EG 6.32024-03-09
A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file System.cpp. The manipulation of the argument ad_code leads to bu…
- CVE-2024-23368HIGHCVSS 7.8EG 7.82024-07-01
Memory corruption when allocating and accessing an entry in an SMEM partition.
- CVE-2024-23375MEDIUMCVSS 6.7EG 6.72024-10-07
Memory corruption during the network scan request.
- CVE-2024-23378MEDIUMCVSS 6.7EG 6.72024-10-07
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
- CVE-2024-23613CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
- CVE-2024-23614CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
- CVE-2024-23615CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
- CVE-2024-23616CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
- CVE-2024-23617CRITICALCVSS 9.6EG 9.62024-01-26
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
- CVE-2024-23621CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution.
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →