Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Au
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Sna
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna
When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o
Out of bound access can occur while processing peer info in IBSS connection mode due to lack of upper bounds check to en
Buffer overwrite can occur in IEEE80211 header filling function due to lack of range check of array index received from
Out of bounds memcpy can occur by providing the embedded NULL character string and length greater than the actual string
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. Mounting a m
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tv
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CW
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries
SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow
A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash)
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem
process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 impl
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffD
Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific par
SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C
An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implem
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmw
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow
Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allo
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that resu
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a
An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera
Frequently Asked Questions
What is CWE-120?
CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-120?
There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.
How can I protect against CWE-120 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.
Detect CWE-120 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.
Get Started