A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability a
A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu
A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue af
A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. This affec
A vulnerability has been found in code-projects Tourism Management System 1.0 and classified as critical. This vulnerabi
A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Aff
Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow
A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the
A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the fi
The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET
The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf
Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced
A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attack
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification,
Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which
Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related t
Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict
Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is r
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db364
A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /us
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrati
NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability all
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2,
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly larg
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affect
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulner
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS
Frequently Asked Questions
What is CWE-120?
CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-120?
There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.
How can I protect against CWE-120 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.
Detect CWE-120 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.
Get Started