CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 62 of 87
- CVE-2024-56590MEDIUMCVSS 5.5EG 5.52024-12-27
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet This fixes not checking if skb really contains an ACL header otherwise the code may attempt to acc…
- CVE-2024-56805MEDIUMCVSS 5.4EG 5.42025-06-06
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have alre…
- CVE-2024-56914MEDIUMCVSS 5.7EG 5.72025-01-22
D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
- CVE-2024-57184MEDIUMCVSS 5.5EG 5.52025-01-24
An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.
- CVE-2024-57376HIGHCVSS 8.8EG 8.82025-01-28
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.
- CVE-2024-57392HIGHCVSS 7.5EG 7.52025-02-06
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
- CVE-2024-57471CRITICALCVSS 9.8EG 9.82025-01-14
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to …
- CVE-2024-57473CRITICALCVSS 9.8EG 9.82025-01-14
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or exec…
- CVE-2024-57479CRITICALCVSS 9.8EG 9.82025-01-14
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execu…
- CVE-2024-57480CRITICALCVSS 9.8EG 9.82025-01-14
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute…
- CVE-2024-57482CRITICALCVSS 9.8EG 9.82025-01-14
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to cr…
- CVE-2024-57483CRITICALCVSS 9.8EG 9.82025-01-14
Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
- CVE-2024-57509HIGHCVSS 7.8EG 7.82025-01-29
Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.
- CVE-2024-57510HIGHCVSS 7.8EG 7.82025-01-29
Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.
- CVE-2024-57513MEDIUMCVSS 6.5EG 6.52025-01-29
A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.
- CVE-2024-57537MEDIUMCVSS 6.3EG 6.32025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.
- CVE-2024-57538MEDIUMCVSS 6.5EG 6.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.
- CVE-2024-57540MEDIUMCVSS 6.5EG 6.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.
- CVE-2024-57541MEDIUMCVSS 5.5EG 5.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.
- CVE-2024-57543MEDIUMCVSS 5.5EG 5.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.
- CVE-2024-57544MEDIUMCVSS 5.5EG 5.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.
- CVE-2024-57545MEDIUMCVSS 5.5EG 5.52025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.
- CVE-2024-57577MEDIUMCVSS 5.7EG 5.72025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
- CVE-2024-57578HIGHCVSS 8.8EG 8.82025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.
- CVE-2024-57579CRITICALCVSS 9.8EG 9.82025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.
- CVE-2024-57580CRITICALCVSS 9.8EG 9.82025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
- CVE-2024-57581CRITICALCVSS 9.8EG 9.82025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
- CVE-2024-57582CRITICALCVSS 9.8EG 9.82025-01-16
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.
- CVE-2024-57703CRITICALCVSS 9.8EG 9.82025-01-16
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.
- CVE-2024-58106MEDIUMCVSS 4.6EG 4.62025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58107HIGHCVSS 7.5EG 7.52025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58108MEDIUMCVSS 4.6EG 4.62025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58109MEDIUMCVSS 4.6EG 4.62025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58110MEDIUMCVSS 4.6EG 4.62025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-5974HIGHCVSS 7.2EG 7.22024-07-09
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 th…
- CVE-2024-6142HIGHCVSS 8.8EG 8.82024-06-19
Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authenticat…
- CVE-2024-6143HIGHCVSS 8.8EG 8.82024-06-19
Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authenticati…
- CVE-2024-6198HIGHCVSS 7.7EG 7.72025-04-25
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsin…
- CVE-2024-6199HIGHCVSS 7.7EG 7.72025-04-25
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem…
- CVE-2024-6343MEDIUMCVSS 4.9EG 4.92024-09-03
A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38…
- CVE-2024-6350MEDIUMCVSS 6.5EG 6.52025-01-08
A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.
- CVE-2024-6351MEDIUMCVSS 4.3EG 4.32025-01-28
A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
- CVE-2024-6352MEDIUMCVSS 4.3EG 4.32025-01-13
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
- CVE-2024-6563HIGHCVSS 7.5EG 7.52024-07-08
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program files https://github.Com/renesas-rcar/arm-t…
- CVE-2024-6564MEDIUMCVSS 6.7EG 6.72024-07-08
Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead to a full bypass of secure boot.
- CVE-2024-6604HIGHCVSS 7.5EG 7.52024-07-09
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary …
- CVE-2024-6918HIGHCVSS 7.5EG 7.52024-08-20
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.
- CVE-2024-7157HIGHCVSS 8.8EG 8.82024-07-28
A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_ho…
- CVE-2024-7172HIGHCVSS 8.8EG 8.82024-07-28
A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this vulnerability is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument…
- CVE-2024-7173HIGHCVSS 8.8EG 8.82024-07-29
A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password/http_…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →