CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 61 of 87
- CVE-2024-52030MEDIUMCVSS 5.7EG 5.72024-11-05
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2024-52059HIGHCVSS 7.8EG 7.82024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.This issue a…
- CVE-2024-52060HIGHCVSS 7.8EG 7.82024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service, Recording Service, Queuing Service, Observability Collector Service, Cloud Discovery Service) allows Buffer …
- CVE-2024-52061CRITICALCVSS 9.8EG 9.82024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Queuing Service, Recording Service, Routing Service) allows Overflow Variables and Tags.This issue affects Co…
- CVE-2024-52062HIGHCVSS 7.8EG 7.82024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6…
- CVE-2024-52063HIGHCVSS 8.6EG 8.62024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 befor…
- CVE-2024-52064HIGHCVSS 7.1EG 7.12024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6…
- CVE-2024-52065HIGHCVSS 7.1EG 7.12024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional:…
- CVE-2024-52066HIGHCVSS 7.8EG 7.82024-12-13
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.…
- CVE-2024-5243HIGHCVSS 7.5EG 7.52024-05-23
TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not require…
- CVE-2024-52531HIGHCVSS 6.5EG 8.42024-11-11
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., a…
- CVE-2024-52533CRITICALCVSS 9.8EG 9.82024-11-11
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
- CVE-2024-52711MEDIUMCVSS 5.7EG 5.72024-11-19
DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.
- CVE-2024-52714CRITICALCVSS 9.8EG 9.82024-11-19
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
- CVE-2024-52754MEDIUMCVSS 4.9EG 4.92024-11-20
D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.
- CVE-2024-52755MEDIUMCVSS 4.9EG 4.92024-11-21
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.
- CVE-2024-52757MEDIUMCVSS 4.9EG 4.92024-11-20
D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.
- CVE-2024-52759CRITICALCVSS 9.8EG 9.82024-11-19
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.
- CVE-2024-52949CRITICALCVSS 7.5EG 9.82024-12-16
iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.
- CVE-2024-53013MEDIUMCVSS 6.6EG 6.62025-06-03
Memory corruption may occur while processing voice call registration with user.
- CVE-2024-53027HIGHCVSS 7.5EG 7.52025-03-03
Transient DOS may occur while processing the country IE.
- CVE-2024-5305HIGHCVSS 7.8EG 7.82024-06-06
Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is requir…
- CVE-2024-53192MEDIUMCVSS 5.5EG 5.52024-12-27
In the Linux kernel, the following vulnerability has been resolved: clk: clk-loongson2: Fix potential buffer overflow in flexible-array member access Flexible-array member `hws` in `struct clk_hw_onecell_data` is annotated with the `coun…
- CVE-2024-53319HIGHCVSS 7.5EG 7.52025-01-31
A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause Denial of Service (DoS) via escaping special XML characters.
- CVE-2024-53320CRITICALCVSS 9.8EG 9.82025-01-31
Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.
- CVE-2024-53334HIGHCVSS 8.8EG 8.82024-11-21
TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
- CVE-2024-53335HIGHCVSS 7.8EG 7.82024-11-21
TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
- CVE-2024-53379HIGHCVSS 7.5EG 7.52025-01-23
Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to trigger a Denial-of-Service via a malfor…
- CVE-2024-53425MEDIUMCVSS 6.2EG 6.22024-11-21
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application cras…
- CVE-2024-53426MEDIUMCVSS 6.2EG 6.22024-11-21
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
- CVE-2024-53589HIGHCVSS 8.4EG 8.42024-12-05
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
- CVE-2024-53681MEDIUMCVSS 5.5EG 5.52025-01-15
In the Linux kernel, the following vulnerability has been resolved: nvmet: Don't overflow subsysnqn nvmet_root_discovery_nqn_store treats the subsysnqn string like a fixed size buffer, even though it is dynamically allocated to the size …
- CVE-2024-53695CRITICALCVSS 9.1EG 9.12025-03-07
A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the followi…
- CVE-2024-53901MEDIUMCVSS 5.5EG 5.52024-11-24
The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image.
- CVE-2024-54105MEDIUMCVSS 5.1EG 5.12024-12-12
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-5412HIGHCVSS 7.5EG 7.52024-09-03
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a…
- CVE-2024-54568MEDIUMCVSS 4.3EG 4.32025-08-29
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an unexpected app termination.
- CVE-2024-5463MEDIUMCVSS 6.5EG 6.52024-06-04
A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files containing non-sensitive information and condu…
- CVE-2024-54887HIGHCVSS 8.0EG 8.02025-01-09
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitra…
- CVE-2024-55045HIGHCVSS 7.3EG 7.32026-05-13
Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.
- CVE-2024-55194CRITICALCVSS 9.8EG 9.82025-01-23
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
- CVE-2024-55564CRITICALCVSS 9.8EG 9.82024-12-09
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
- CVE-2024-5564HIGHCVSS 8.1EG 8.12024-05-31
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly v…
- CVE-2024-56450MEDIUMCVSS 6.3EG 6.32025-01-08
Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56452MEDIUMCVSS 5.5EG 5.52025-01-08
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56453MEDIUMCVSS 6.8EG 6.82025-01-08
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56454MEDIUMCVSS 5.5EG 5.52025-01-08
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56455MEDIUMCVSS 5.5EG 5.52025-01-08
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56456MEDIUMCVSS 6.8EG 6.82025-01-08
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-56557MEDIUMCVSS 5.5EG 5.52024-12-27
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer The AD7923 was updated to support devices with 8 channels, but the size of tx_buf and ring_xfer was not in…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →