CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 56 of 87
- CVE-2024-37017HIGHCVSS 8.1EG 8.12024-05-31
asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.
- CVE-2024-37040MEDIUMCVSS 5.4EG 5.42024-06-12
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP reque…
- CVE-2024-37041HIGHCVSS 7.2EG 7.22024-11-22
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute cod…
- CVE-2024-37044HIGHCVSS 7.2EG 7.22024-11-22
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute cod…
- CVE-2024-37047MEDIUMCVSS 6.5EG 6.52024-11-22
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute cod…
- CVE-2024-37049MEDIUMCVSS 6.5EG 6.52024-11-22
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute cod…
- CVE-2024-37050MEDIUMCVSS 6.5EG 6.52024-11-22
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute cod…
- CVE-2024-37184CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi rep_as_bridge() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP …
- CVE-2024-37305HIGHCVSS 8.2EG 8.22024-06-17
oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handl…
- CVE-2024-37357CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP requ…
- CVE-2024-37571MEDIUMCVSS 4.3EG 4.32024-06-26
Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter.
- CVE-2024-37606MEDIUMCVSS 6.5EG 6.52024-12-17
A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
- CVE-2024-37607MEDIUMCVSS 6.5EG 6.52024-12-17
A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
- CVE-2024-37632CRITICALCVSS 9.8EG 9.82024-06-13
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
- CVE-2024-37635CRITICALCVSS 9.8EG 9.82024-06-13
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
- CVE-2024-37637CRITICALCVSS 9.8EG 9.82024-06-14
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.
- CVE-2024-37816MEDIUMCVSS 4.2EG 4.22024-11-27
Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.
- CVE-2024-37861CRITICALCVSS 9.8EG 9.82024-12-05
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.
- CVE-2024-37863CRITICALCVSS 9.8EG 9.82024-12-05
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.
- CVE-2024-38409HIGHCVSS 7.8EG 7.82024-11-04
Memory corruption while station LL statistic handling.
- CVE-2024-38423HIGHCVSS 7.8EG 7.82024-11-04
Memory corruption while processing GPU page table switch.
- CVE-2024-38441CRITICALCVSS 9.8EG 9.82024-06-16
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.
- CVE-2024-38541CRITICALCVSS 9.8EG 9.82024-06-19
In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalias() In of_modalias(), if the buffer happens to be too small even for the 1st snprintf() call, the len parameter will b…
- CVE-2024-38576HIGHCVSS 7.1EG 7.12024-06-19
In the Linux kernel, the following vulnerability has been resolved: rcu: Fix buffer overflow in print_cpu_stall_info() The rcuc-starvation output from print_cpu_stall_info() might overflow the buffer if there is a huge difference in jiff…
- CVE-2024-38577HIGHCVSS 7.8EG 7.82024-06-19
In the Linux kernel, the following vulnerability has been resolved: rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow There is a possibility of buffer overflow in show_rcu_tasks_trace_gp_kthread() if counters, passed to spri…
- CVE-2024-3871CRITICALCVSS 9.8EG 9.82024-04-16
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of …
- CVE-2024-38922CRITICALCVSS 9.8EG 9.82024-12-06
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.
- CVE-2024-38951MEDIUMCVSS 6.5EG 6.52024-06-25
A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.
- CVE-2024-38952HIGHCVSS 7.5EG 7.52024-06-25
PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.
- CVE-2024-39129MEDIUMCVSS 5.3EG 5.32024-06-27
Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /src/PayloadBuf.cpp.
- CVE-2024-39134HIGHCVSS 7.5EG 7.52024-06-27
A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.
- CVE-2024-39181MEDIUMCVSS 6.5EG 6.52024-07-09
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers to cause a Denial of Service (DoS) v…
- CVE-2024-39207HIGHCVSS 8.2EG 8.22024-06-27
lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.
- CVE-2024-39288CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-39291HIGHCVSS 7.8EG 7.82024-06-24
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_ cp_compute_microcode() and rlc_microcode() The function gfx_v9_4_3_init_microcode in gfx_v9_4_3.c was generating about po…
- CVE-2024-39294CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi set_wzdgw4G() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP re…
- CVE-2024-39299CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the qos.cgi qos_sta_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HT…
- CVE-2024-39349CRITICALCVSS 9.8EG 9.82024-06-28
A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via u…
- CVE-2024-39358CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi set_wzap() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP reque…
- CVE-2024-39370CRITICALCVSS 9.1EG 9.12025-01-14
An arbitrary code execution vulnerability exists in the adm.cgi set_MeshAp() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated H…
- CVE-2024-39480HIGHCVSS 7.8EG 7.82024-07-05
In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol …
- CVE-2024-39538MEDIUMCVSS 6.5EG 6.52024-07-11
A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS)…
- CVE-2024-39543MEDIUMCVSS 6.5EG 6.52024-07-11
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR pack…
- CVE-2024-39750HIGHCVSS 8.8EG 8.82025-01-25
IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
- CVE-2024-39756CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi rep_as_router() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP …
- CVE-2024-39768CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-39769CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-39770CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-39774CRITICALCVSS 9.1EG 9.12025-01-14
A buffer overflow vulnerability exists in the adm.cgi set_sys_adm() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP re…
- CVE-2024-39801CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →