iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a
GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows
GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Memory Corruption when handling power management requests with improperly sized input/output buffers.
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a
Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulner
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to lo
In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This coul
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
Memory Corruption when handling malformed request parameters in the fingerprint TA.
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can
A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security A
FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling.
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bl
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-
Leawo Prof. Media 11.0.0.1 contains a denial of service vulnerability that allows attackers to crash the application by
Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by o
NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing
Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to
Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application
Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers
Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting
aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th
P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by
APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the applicatio
GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by
Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by o
SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers t
SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers
TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers t
Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the
Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to
ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by
Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by s
Frequently Asked Questions
What is CWE-120?
CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-120?
There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.
How can I protect against CWE-120 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.
Detect CWE-120 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.
Get Started