Vulnerabilities (CVE)

Filtered by CWE-120
Total 3990 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57473 1 H3c 2 N12, N12 Firmware 2026-06-17 N/A 9.8 CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
CVE-2024-57471 1 H3c 2 N12, N12 Firmware 2026-06-17 N/A 9.8 CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
CVE-2024-57392 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
CVE-2024-57376 1 Dlink 12 Dsr-1000n, Dsr-1000n Firmware, Dsr-150 and 9 more 2026-06-17 N/A 8.8 HIGH
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.
CVE-2024-57184 1 Gpac 1 Gpac 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.
CVE-2024-56914 1 Dlink 2 Dsl-3782, Dsl-3782 Firmware 2026-06-17 N/A 5.7 MEDIUM
D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
CVE-2024-56805 1 Qnap 2 Qts, Quts Hero 2026-06-17 N/A 5.4 MEDIUM
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later QuTS hero h5.2.4.3079 build 20250321 and later
CVE-2024-56590 1 Linux 1 Linux Kernel 2026-06-17 N/A 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet This fixes not checking if skb really contains an ACL header otherwise the code may attempt to access some uninitilized/invalid memory past the valid skb->data.
CVE-2024-56557 1 Linux 1 Linux Kernel 2026-06-17 N/A 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer The AD7923 was updated to support devices with 8 channels, but the size of tx_buf and ring_xfer was not increased accordingly, leading to a potential buffer overflow in ad7923_update_scan_mode().
CVE-2024-56456 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.8 MEDIUM
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-56455 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-56454 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-56453 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.8 MEDIUM
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-56452 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-56450 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.3 MEDIUM
Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-55564 2026-06-17 N/A 9.8 CRITICAL
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.
CVE-2024-55194 1 Openimageio 1 Openimageio 2026-06-17 N/A 9.8 CRITICAL
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CVE-2024-54887 1 Tp-link 2 Tl-wr940n, Tl-wr940n Firmware 2026-06-17 N/A 8.0 HIGH
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.
CVE-2024-54568 1 Apple 1 Macos 2026-06-17 N/A 4.3 MEDIUM
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an unexpected app termination.
CVE-2024-54105 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.