CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 57 of 87
- CVE-2024-39802CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-39803CRITICALCVSS 9.1EG 9.12025-01-14
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticate…
- CVE-2024-40083CRITICALCVSS 9.6EG 9.62024-10-21
A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into…
- CVE-2024-40084CRITICALCVSS 9.6EG 9.62024-10-21
A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via exceptionally long HTTP methods or paths.
- CVE-2024-40085CRITICALCVSS 9.6EG 9.62024-10-21
A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via pppoe_username and pppoe_password fields being larger t…
- CVE-2024-40086CRITICALCVSS 9.6EG 9.62024-10-21
A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via a password field larger than 64 bytes in leng…
- CVE-2024-40130CRITICALCVSS 9.8EG 9.82024-07-16
open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.
- CVE-2024-4020HIGHCVSS 8.8EG 8.82024-04-20
A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument entrys leads to buffer overflow. The attack…
- CVE-2024-40415CRITICALCVSS 9.8EG 9.82024-07-15
A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
- CVE-2024-40427HIGHCVSS 7.9EG 7.92025-01-07
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute
- CVE-2024-40494CRITICALCVSS 9.8EG 9.82024-10-22
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.
- CVE-2024-40536MEDIUMCVSS 5.3EG 5.32024-07-16
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the config_3g_para function.
- CVE-2024-40568CRITICALCVSS 9.8EG 9.82024-09-18
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component
- CVE-2024-40659MEDIUMCVSS 5.5EG 5.52024-09-11
In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This c…
- CVE-2024-40674MEDIUMCVSS 5.3EG 5.32025-01-28
In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. Use…
- CVE-2024-40724HIGHCVSS 7.8EG 8.42024-07-19
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.
- CVE-2024-40902HIGHCVSS 7.8EG 7.82024-07-12
In the Linux kernel, the following vulnerability has been resolved: jfs: xattr: fix buffer overflow for invalid xattr When an xattr size is not what is expected, it is printed out to the kernel log in hex format as a form of debugging. …
- CVE-2024-41038MEDIUMCVSS 5.5EG 5.52024-07-29
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The …
- CVE-2024-41039HIGHCVSS 7.8EG 7.82024-07-29
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix overflow checking of wmfw header Fix the checking that firmware file buffer is large enough for the wmfw header, to prevent overrunning the buffer.…
- CVE-2024-41176HIGHCVSS 7.3EG 7.32024-08-27
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.
- CVE-2024-41206MEDIUMCVSS 6.5EG 6.52024-11-14
A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a crafted TS video file.
- CVE-2024-41209HIGHCVSS 8.8EG 8.82024-11-14
A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.
- CVE-2024-41217MEDIUMCVSS 6.5EG 6.52024-11-14
A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.
- CVE-2024-41285CRITICALCVSS 9.8EG 9.82024-08-26
A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.
- CVE-2024-4143CRITICALCVSS 9.8EG 9.82024-07-15
A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware updates to mitigate this vulnerability.
- CVE-2024-41433CRITICALCVSS 9.8EG 9.82024-09-03
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that th…
- CVE-2024-41435HIGHCVSS 7.5EG 7.52024-09-03
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
- CVE-2024-41436HIGHCVSS 7.5EG 7.52024-09-03
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
- CVE-2024-41464HIGHCVSS 7.5EG 7.52024-07-24
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic
- CVE-2024-41588HIGHCVSS 8.0EG 8.02024-10-03
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncp…
- CVE-2024-41596HIGHCVSS 8.0EG 8.02024-10-03
Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.
- CVE-2024-41631HIGHCVSS 7.5EG 7.52024-07-29
Buffer Overflow vulnerability in host-host NEUQ_board v.1.0 allows a remote attacker to cause a denial of service via the password.h component.
- CVE-2024-41660CRITICALCVSS 9.8EG 9.82024-07-31
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to …
- CVE-2024-42011HIGHCVSS 7.5EG 7.52024-10-28
The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.
- CVE-2024-42040HIGHCVSS 8.1EG 8.12024-08-23
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind …
- CVE-2024-42238MEDIUMCVSS 5.5EG 5.52024-08-07
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if a block header is longer than the amount of data left in the file…
- CVE-2024-42520CRITICALCVSS 9.8EG 9.82024-08-12
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
- CVE-2024-42543CRITICALCVSS 9.8EG 9.82024-08-12
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- CVE-2024-42545CRITICALCVSS 9.8EG 9.82024-08-12
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
- CVE-2024-42546CRITICALCVSS 9.8EG 9.82024-08-12
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.
- CVE-2024-42547CRITICALCVSS 9.8EG 9.82024-08-12
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- CVE-2024-42642CRITICALCVSS 6.7EG 9.82024-09-04
Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerabili…
- CVE-2024-42812CRITICALCVSS 9.8EG 9.82024-08-19
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or e…
- CVE-2024-42813CRITICALCVSS 9.8EG 9.82024-08-19
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device t…
- CVE-2024-43055HIGHCVSS 7.8EG 7.82025-03-03
Memory corruption while processing camera use case IOCTL call.
- CVE-2024-43700HIGHCVSS 7.8EG 7.82024-08-29
xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, …
- CVE-2024-43767HIGHCVSS 8.8EG 8.82025-01-03
In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not …
- CVE-2024-44144MEDIUMCVSS 5.5EG 5.52024-10-28
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously craf…
- CVE-2024-44157MEDIUMCVSS 5.5EG 5.52024-10-11
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
- CVE-2024-44160HIGHCVSS 5.5EG 7.82024-09-17
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. Processing a maliciously crafted texture may lead to unexpected app termination.
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →