NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communic
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Ech
In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic due to the lack of validation
An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter.
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary pr
Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by
A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.
An issue was discovered in Foxit PhantomPDF before 8.3.11. It has a buffer overflow because a looping correction does no
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_c
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentic
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attac
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, w
A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on
An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradl
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradl
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradl
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Ca
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator
MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the f
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated
Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.38,
A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt sy
A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflo
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.52,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.48,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects DGN2200 before 1.0.0.58
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D8500 before 1.0.3.43,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R7800 before 1.0.2.36,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D7800 before 1.0.1.34,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R8300 before 1.0.2.106
Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6400 before 1.0.0.74,
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.40,
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel be
Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.4
Frequently Asked Questions
What is CWE-120?
CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-120?
There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.
How can I protect against CWE-120 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.
Detect CWE-120 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.
Get Started