CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 54 of 87
- CVE-2024-27407HIGHCVSS 8.4EG 8.42024-05-17
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fixed overflow check in mi_enum_attr()
- CVE-2024-27572HIGHCVSS 7.5EG 7.52024-03-01
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-27619HIGHCVSS 7.3EG 7.32024-03-29
Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer overflow if file or files uploaded are greater than available ram. Ftp server al…
- CVE-2024-27628HIGHCVSS 8.1EG 8.12024-06-28
Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.
- CVE-2024-27878MEDIUMCVSS 6.7EG 6.72024-07-29
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2024-27908MEDIUMCVSS 4.9EG 4.92024-04-05
A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.
- CVE-2024-28564MEDIUMCVSS 6.2EG 6.22024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when reading images in EXR format.
- CVE-2024-28565MEDIUMCVSS 5.5EG 5.52024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the psdParser::ReadImageData() function when reading images in PSD format.
- CVE-2024-28569HIGHCVSS 7.8EG 7.82024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.
- CVE-2024-28570MEDIUMCVSS 5.5EG 5.52024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format.
- CVE-2024-28576MEDIUMCVSS 5.5EG 5.52024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_tcp_destroy() function when reading images in J2K format.
- CVE-2024-28583HIGHCVSS 7.8EG 7.82024-03-20
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.
- CVE-2024-28639CRITICALCVSS 9.8EG 9.82024-03-16
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
- CVE-2024-28759MEDIUMCVSS 4.3EG 4.32024-05-14
A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.
- CVE-2024-29159CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29166MEDIUMCVSS 5.7EG 5.72024-05-14
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29195MEDIUMCVSS 6.0EG 6.02024-03-26
The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparou…
- CVE-2024-29243CRITICALCVSS 9.8EG 9.82024-03-21
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.
- CVE-2024-29244MEDIUMCVSS 5.3EG 5.32024-03-21
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.
- CVE-2024-29506HIGHCVSS 8.8EG 8.82024-07-03
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
- CVE-2024-29507MEDIUMCVSS 5.4EG 5.42024-07-03
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
- CVE-2024-29645HIGHCVSS 7.8EG 7.82024-12-02
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.
- CVE-2024-29646CRITICALCVSS 9.8EG 9.82024-12-17
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
- CVE-2024-29671CRITICALCVSS 9.8EG 9.82024-12-16
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
- CVE-2024-30020HIGHCVSS 8.1EG 8.12024-05-14
Windows Cryptographic Services Remote Code Execution Vulnerability
- CVE-2024-30164MEDIUMCVSS 6.7EG 6.72024-05-28
Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the …
- CVE-2024-30165HIGHCVSS 7.1EG 7.12024-05-28
Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.
- CVE-2024-30259HIGHCVSS 8.2EG 8.22024-05-14
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflo…
- CVE-2024-30584CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
- CVE-2024-30593CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.
- CVE-2024-30602CRITICALCVSS 9.8EG 9.82024-03-28
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
- CVE-2024-30620CRITICALCVSS 9.8EG 9.82024-04-02
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
- CVE-2024-30628CRITICALCVSS 9.8EG 9.82024-03-29
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.
- CVE-2024-30635CRITICALCVSS 9.8EG 9.82024-03-29
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
- CVE-2024-30799MEDIUMCVSS 4.4EG 4.42024-04-22
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.
- CVE-2024-30962HIGHCVSS 7.8EG 7.82024-12-05
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
- CVE-2024-31007MEDIUMCVSS 5.5EG 5.52024-10-21
Buffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected component is IrfanView 32bit 4.66 with plugin formats.dll.
- CVE-2024-31040LOWCVSS 2.7EG 2.72024-04-17
Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
- CVE-2024-3119CRITICALCVSS 9.0EG 9.02024-04-10
A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy he…
- CVE-2024-3120CRITICALCVSS 9.0EG 9.02024-04-10
A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and s…
- CVE-2024-31225HIGHCVSS 8.3EG 8.32024-05-01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The `_on_rd_init()` function does not implement a size check before copying data to the `_r…
- CVE-2024-31504HIGHCVSS 7.5EG 7.52024-07-08
Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.
- CVE-2024-31670MEDIUMCVSS 6.3EG 6.32024-12-12
rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.
- CVE-2024-31950MEDIUMCVSS 6.5EG 6.52024-04-07
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
- CVE-2024-31951MEDIUMCVSS 6.5EG 6.52024-04-07
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths …
- CVE-2024-31963MEDIUMCVSS 6.4EG 6.42024-05-02
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker to conduct a buffer overflow attack due …
- CVE-2024-32017CRITICALCVSS 9.8EG 9.82024-05-01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the `gcoap_dns_server_proxy_get()` function contains a small typo that ma…
- CVE-2024-32018HIGHCVSS 8.8EG 8.82024-05-01
RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. Most codebases define assertion macros which compile to a no-op on non-debug builds. If ass…
- CVE-2024-32228MEDIUMCVSS 6.6EG 6.62024-07-01
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
- CVE-2024-32230HIGHCVSS 7.8EG 7.82024-07-01
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →