Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack
Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local
Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to cras
FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyin
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to
hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. Wh
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. T
NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18
Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb frags[] overflow in r
RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by s
Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash t
iCash 7.6.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying a
Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application b
P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows
A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/fo
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma
A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the func
A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affecte
A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is t
A flaw has been found in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. This affects the function rtsp_p
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1
A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
Frequently Asked Questions
What is CWE-120?
CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-120?
There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.
How can I protect against CWE-120 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.
Detect CWE-120 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.
Get Started