Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-120

MITRE ↗

CWE-120

900
CRITICAL
2,344
HIGH
947
MEDIUM
52
LOW
4,280 CVEs · Page 44/86
5.2
CVE-2021-46746

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged

5.1
CVE-2024-54105

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect

5.0
CVE-2023-50361

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

5.0
CVE-2023-50362

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

4.9
CVE-2024-27908

A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of

4.9
CVE-2024-6343

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG F

4.9
CVE-2024-52754

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

4.9
CVE-2024-52757

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp funct

4.9
CVE-2024-52755

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp f

4.9
CVE-2024-9197

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B f

4.6
CVE-2024-25373

Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function

4.5
CVE-2024-8882

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and ea

4.4
CVE-2024-27225

In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could

4.4
CVE-2023-52346

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information

4.4
CVE-2024-30799

An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of serv

4.4
CVE-2022-49040

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functional

4.4
CVE-2022-49041

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functiona

4.3
CVE-2024-25394

A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or

4.3
CVE-2024-28759

A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.

4.3
CVE-2024-37571

Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensiti

4.3
CVE-2024-45619

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted

4.3
CVE-2022-20846

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauth

4.3
CVE-2022-29974

AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is

4.2
CVE-2023-42757

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by

4.2
CVE-2024-37816

Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.

3.9
CVE-2024-45620

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, w

3.8
CVE-2023-45039

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45040

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45041

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45042

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45043

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45044

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-41292

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45035

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45036

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.8
CVE-2023-45037

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.6
CVE-2023-51796

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the

3.3
CVE-2024-25196

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow v

3.0
CVE-2023-6948

A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on

2.7
CVE-2024-31040

Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers

CVE-2022-23817

Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious tr

CVE-2024-12373

A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a b

10.0
CVE-2023-24482

A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS

10.0
CVE-2021-33972

Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.

10.0
CVE-2021-33975

Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate priv

10.0
CVE-2023-1424

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation

9.9
CVE-2023-36355

TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg

9.8
CVE-2022-45995

There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the

9.8
CVE-2023-22741

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions

9.8
CVE-2023-24169

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.

Frequently Asked Questions

What is CWE-120?

CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-120?

There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.

How can I protect against CWE-120 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.

Detect CWE-120 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.

Get Started