Vulnerabilities (CVE)

Filtered by CWE-120
Total 3648 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-51823 1 Libcsp 1 Libcsp 2025-08-14 N/A 6.5 MEDIUM
libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy the interface name into a structure member (ctx->name) without validating the input length.
CVE-2025-51824 1 Libcsp 1 Libcsp 2025-08-14 N/A 6.5 MEDIUM
libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.
CVE-2020-25969 1 Gnuplot 1 Gnuplot 2025-08-14 N/A 9.8 CRITICAL
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
CVE-2015-7747 3 Audiofile, Canonical, Fedoraproject 3 Audiofile, Ubuntu Linux, Fedora 2025-08-13 6.8 MEDIUM 8.8 HIGH
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
CVE-2025-8760 2025-08-13 10.0 HIGH 9.8 CRITICAL
A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.
CVE-2025-25527 1 Ruijie 2 Rg-nbr2600s, Rg-nbr2600s Firmware 2025-08-13 N/A 5.1 MEDIUM
Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2020-19695 1 F5 1 Njs 2025-08-12 N/A 9.8 CRITICAL
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
CVE-2020-19692 1 F5 1 Njs 2025-08-12 N/A 9.8 CRITICAL
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
CVE-2025-0689 1 Gnu 1 Grub2 2025-08-12 N/A 6.7 MEDIUM
When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.
CVE-2025-8854 2025-08-11 N/A N/A
Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.
CVE-2025-54642 1 Huawei 2 Emui, Harmonyos 2025-08-11 N/A 6.7 MEDIUM
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-54641 1 Huawei 2 Emui, Harmonyos 2025-08-11 N/A 6.7 MEDIUM
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2023-33068 1 Qualcomm 226 9206 Lte Modem, 9206 Lte Modem Firmware, Aqt1000 and 223 more 2025-08-11 N/A 6.7 MEDIUM
Memory corruption in Audio while processing IIR config data from AFE calibration block.
CVE-2025-27043 1 Qualcomm 412 Ar8035, Ar8035 Firmware, Csr8811 and 409 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing manipulated payload in video firmware.
CVE-2024-45541 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 99 more 2025-08-11 N/A 7.8 HIGH
Memory corruption when IOCTL call is invoked from user-space to read board data.
CVE-2023-43519 1 Qualcomm 268 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 265 more 2025-08-11 N/A 7.3 HIGH
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
CVE-2023-43542 1 Qualcomm 418 9205 Lte Modem, 9205 Lte Modem Firmware, Aqt1000 and 415 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2024-21480 1 Qualcomm 230 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 227 more 2025-08-11 N/A 7.3 HIGH
Memory corruption while playing audio file having large-sized input buffer.
CVE-2023-28580 1 Qualcomm 88 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 85 more 2025-08-11 N/A 6.7 MEDIUM
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
CVE-2023-28547 1 Qualcomm 604 215 Mobile, 215 Mobile Firmware, 315 5g Iot and 601 more 2025-08-11 N/A 8.4 HIGH
Memory corruption in SPS Application while requesting for public key in sorter TA.