CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
2,880 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 1 of 58
- CVE-2006-3100CRITICALCVSS 9.8EG 9.82019-11-06
termpkg 3.3 suffers from buffer overflow.
- CVE-2009-0948CRITICALCVSS 9.8EG 9.82021-06-02
Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.
- CVE-2009-4067MEDIUMCVSS 6.8EG 6.82020-02-11
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or ta…
- CVE-2009-5041CRITICALCVSS 9.8EG 9.82019-10-31
overkill has buffer overflow via long player names that can corrupt data on the server machine
- CVE-2010-3843HIGHCVSS 7.8EG 7.82021-05-28
The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/ec_gtk_conf.c), an unchecked sscanf() cal…
- CVE-2010-3844HIGHCVSS 8.8EG 8.82019-11-12
An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.
- CVE-2010-5333CRITICALCVSS 9.8EG 9.82019-09-13
The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution. An SEH-overwrite buffer overflow …
- CVE-2011-10005MEDIUMCVSS 6.3EG 6.32024-01-16
A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely.…
- CVE-2011-1145HIGHCVSS 7.8EG 7.82019-11-14
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
- CVE-2012-3407HIGHCVSS 7.8EG 7.82019-11-22
plow has local buffer overflow vulnerability
- CVE-2012-6122HIGHCVSS 7.5EG 7.52019-10-31
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
- CVE-2013-1592CRITICALCVSS 9.8EG 9.82020-01-23
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP0…
- CVE-2013-1595CRITICALCVSS 9.8EG 9.82020-01-24
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or…
- CVE-2013-2075HIGHCVSS 8.8EG 8.82019-10-31
Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer v…
- CVE-2013-3488HIGHCVSS 7.8EG 7.82020-01-31
Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to execute arbitrary code via a crafted MPEG-2 Transport Stream (M2TS) file.
- CVE-2013-3489HIGHCVSS 7.8EG 7.82020-01-31
Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary code via a crafted RealMedia .rm file
- CVE-2013-4357HIGHCVSS 7.5EG 7.52019-12-31
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
- CVE-2013-4743CRITICALCVSS 9.8EG 9.82019-12-27
Static HTTP Server 1.0 has a Local Overflow
- CVE-2013-7088CRITICALCVSS 9.8EG 9.82019-11-15
ClamAV before 0.97.7 has buffer overflow in the libclamav component
- CVE-2013-7173CRITICALCVSS 9.8EG 9.82020-02-13
Belkin n750 routers have a buffer overflow.
- CVE-2014-1617MEDIUMCVSS 6.5EG 6.52020-02-13
Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of service.
- CVE-2014-1958HIGHCVSS 8.8EG 8.82020-02-06
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2…
- CVE-2014-6310CRITICALCVSS 9.8EG 9.82019-11-22
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.
- CVE-2014-8271MEDIUMCVSS 6.8EG 6.82020-02-06
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
- CVE-2014-9625HIGHCVSS 7.8EG 7.82020-01-24
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow a…
- CVE-2014-9628HIGHCVSS 7.8EG 7.82020-01-24
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitra…
- CVE-2014-9629HIGHCVSS 7.8EG 7.82020-01-24
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted le…
- CVE-2015-0241HIGHCVSS 8.8EG 8.82020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary cod…
- CVE-2015-0243HIGHCVSS 8.8EG 8.82020-01-27
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possi…
- CVE-2015-10065MEDIUMCVSS 5.5EG 9.82023-01-17
A vulnerability classified as critical was found in AenBleidd FiND. This vulnerability affects the function init_result of the file validator/my_validator.cpp. The manipulation leads to buffer overflow. The patch is identified as ee2eef34a…
- CVE-2015-10123HIGHCVSS 8.8EG 8.82024-03-13
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full a…
- CVE-2015-20109MEDIUMCVSS 5.5EG 5.52023-06-25
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library functi…
- CVE-2015-20111CRITICALCVSS 9.8EG 9.82024-11-18
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Cor…
- CVE-2015-2098HIGHCVSS 8.8EG 8.82021-07-22
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; …
- CVE-2015-2099HIGHCVSS 8.8EG 8.82021-07-22
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the Log…
- CVE-2015-5524CRITICALCVSS 9.8EG 9.82020-04-10
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-05-13. There is a buffer overflow in datablock_write because the amount of received data is not validated. The Samsung ID is SVE-2015-4018 (Dece…
- CVE-2015-5684CRITICALCVSS 9.8EG 9.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS…
- CVE-2015-5745MEDIUMCVSS 6.5EG 6.52020-01-23
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
- CVE-2015-6458HIGHCVSS 8.8EG 8.82019-03-21
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
- CVE-2015-7747HIGHCVSS 8.8EG 8.82020-02-19
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio f…
- CVE-2015-7874CRITICALCVSS 9.8EG 9.82020-01-15
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.
- CVE-2015-7890MEDIUMCVSS 5.5EG 5.52020-02-12
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size paramete…
- CVE-2015-8011CRITICALCVSS 9.8EG 9.82020-01-28
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management add…
- CVE-2016-2356CRITICALCVSS 9.8EG 9.82019-10-25
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
- CVE-2016-6559CRITICALCVSS 9.82018-07-13
Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write from memory. The full impact and severity depends on the method of exploit and how the l…
- CVE-2016-8620MEDIUMCVSS 6.52018-08-01
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
- CVE-2017-11003HIGHCVSS 7.82018-01-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating a firmware image, data is read from flash into RAM without checking that the data fits into allotted RAM size.
- CVE-2017-12718HIGHCVSS 8.12018-02-15
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading…
- CVE-2017-13308MEDIUMCVSS 6.7EG 6.72024-12-05
In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. U…
- CVE-2017-13319HIGHCVSS 7.5EG 7.52024-11-27
In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution pri…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →