Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-120

MITRE ↗

CWE-120

900
CRITICAL
2,344
HIGH
947
MEDIUM
52
LOW
4,280 CVEs · Page 53/86
7.5
CVE-2023-36321

Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component

7.5
CVE-2023-46852

In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many

7.5
CVE-2023-47346

Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service v

7.5
CVE-2023-47345

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message wi

7.5
CVE-2023-47347

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages w

7.5
CVE-2023-24294

Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component Netlin

7.5
CVE-2023-47307

Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attack

7.5
CVE-2023-46283

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi

7.5
CVE-2023-46284

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi

7.5
CVE-2023-37457

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0

7.5
CVE-2023-50784

A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker

7.5
CVE-2023-47091

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through

7.4
CVE-2023-28811

There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on th

7.3
CVE-2023-26109

All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel m

7.3
CVE-2023-26110

All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to

7.3
CVE-2023-4590

Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker t

7.2
CVE-2022-43970

A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A st

7.2
CVE-2022-41020

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41021

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41022

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41023

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41024

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41025

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41026

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41027

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41028

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.2
CVE-2022-41029

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

7.1
CVE-2023-27968

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app m

7.1
CVE-2023-0970

Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with i

7.1
CVE-2023-21406

Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based bu

7.1
CVE-2023-20168

A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc

7.1
CVE-2023-4259

Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

7.1
CVE-2023-4264

Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

7.1
CVE-2023-41112

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9

7.0
CVE-2023-2597

In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ

7.0
CVE-2023-5184

Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the

7.0
CVE-2023-48704

ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports i

6.7
CVE-2022-1891

A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local p

6.7
CVE-2022-1892

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local p

6.7
CVE-2022-40137

A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated priv

6.7
CVE-2023-20624

In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of

6.7
CVE-2023-28772

An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

6.7
CVE-2023-0977

A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote use

6.7
CVE-2022-33224

Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.

6.7
CVE-2022-33226

Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from dia

6.7
CVE-2022-33230

Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host

6.7
CVE-2023-21635

Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.

6.7
CVE-2023-21639

Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.

6.7
CVE-2023-21640

Memory corruption in Linux when the file upload API is called with parameters having large buffer.

6.7
CVE-2021-43072

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and bel

Frequently Asked Questions

What is CWE-120?

CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-120?

There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.

How can I protect against CWE-120 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.

Detect CWE-120 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.

Get Started