Vulnerabilities (CVE)

Filtered by CWE-120
Total 4015 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30962 1 Openrobotics 1 Robot Operating System 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
CVE-2024-30799 1 Dronecode 1 Px4 Drone Autopilot 2026-06-17 N/A 4.4 MEDIUM
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.
CVE-2024-30635 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
CVE-2024-30620 1 Tenda 2 Ax1803, Ax1803 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
CVE-2024-30602 1 Tenda 2 Fh1203, Fh1203 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
CVE-2024-30593 1 Tenda 2 Fh1202, Fh1202 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.
CVE-2024-30584 1 Tenda 2 Fh1202, Fh1202 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
CVE-2024-30259 1 Eprosima 1 Fast Dds 2026-06-17 N/A 8.2 HIGH
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.
CVE-2024-30165 2026-06-17 N/A 7.1 HIGH
Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.
CVE-2024-30164 2026-06-17 N/A 6.7 MEDIUM
Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resolution is the same as for CVE-2024-30165, this vulnerability on macOS is not the same as CVE-2024-30165.
CVE-2024-2331 1 Razormist 1 Tourist Reservation System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file System.cpp. The manipulation of the argument ad_code leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-256282 is the identifier assigned to this vulnerability.
CVE-2024-29671 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
CVE-2024-29646 1 Radare 1 Radare2 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
CVE-2024-29645 1 Radare 1 Radare2 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.
CVE-2024-29507 1 Artifex 1 Ghostscript 2026-06-17 N/A 5.4 MEDIUM
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
CVE-2024-29506 1 Artifex 1 Ghostscript 2026-06-17 N/A 8.8 HIGH
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
CVE-2024-29244 1 Szlbt 2 Lbt-t300-mini1, Lbt-t300-mini1 Firmware 2026-06-17 N/A 5.3 MEDIUM
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.
CVE-2024-29243 1 Szlbt 2 Lbt-t300-mini1, Lbt-t300-mini1 Firmware 2026-06-17 N/A 9.8 CRITICAL
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.
CVE-2024-29166 1 Hdfgroup 1 Hdf5 2026-06-17 N/A 5.7 MEDIUM
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2024-29159 1 Hdfgroup 1 Hdf5 2026-06-17 N/A 9.8 CRITICAL
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.