VulnSea

CWE-120

CVEs classified under CWE-120, newest first.

282 CVEsRSS

CVE-2026-90605Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to bu…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2024-53922Medium· 5.7
1w ago

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.

▾ SunlitSamsung · Exynos 8890 firmwareEPSS 0.16%via NVD
CVE-2026-90607Critical· 9.9PoC
1w ago

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2025-64031Low· 2.5PoC⚖ disputed
1w ago

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…

▾ Twilightlibarchive · libarchiveEPSS 0.18%via NVD
CVE-2023-24291Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24287Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24285Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24284Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2026-82772High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec EC1000 series

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

▾ TwilightContec Co., Ltd. · ECE1000EPSS 0.66%via NVD
CVE-2026-82770High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

▾ TwilightContec Co., Ltd. · RP-WAH-SR1EPSS 0.66%via NVD
CVE-2026-16726Medium· 6.8
1w ago

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

▾ Sunlitpanasonic · PANATERM v6EPSS 0.11%via NVD
CVE-2023-24286Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.10%via NVD
CVE-2023-24283Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.11%via NVD
CVE-2026-55209Critical· 9.8
1w ago

resdata is software for reading and writing result files from the Eclipse reservoir simulator

resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRD…

▾ Midnightequinor · resdataEPSS 0.78%via NVD
CVE-2026-90781Medium· 4.4PoC
2w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

▾ TwilightALSA Project · alsa-libEPSS 0.17%via NVD
CVE-2026-90780High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90778High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversize…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-89620High· 7.0
2w ago

kernel: HID: intel-thc-hid: intel-quickspi: validate report size before copy (CVE-2026-89620)

A flaw was found in the Linux kernel's HID Intel QuickSPI driver. A local attacker can exploit a heap buffer overflow by providing a specially crafted report through a `hidraw SET_REPORT/SET_FEATURE ioctl`. This allows the attacker to over…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89619High· 7.0
2w ago

kernel: HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer (CVE-2026-89619)

A flaw was found in the Linux kernel, specifically within the `intel-quickspi` driver. This vulnerability allows a malicious Human Interface Device (HID) to send an oversized report, which is then copied into a buffer without proper size v…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89495Medium· 5.5⚖ disputed
2w ago

kernel: ocfs2: bound namelen in dlm_migrate_request_handler (CVE-2026-89495)

A flaw was found in ocfs2 in the Linux kernel. A malicious or compromised node within a Distributed Lock Manager (DLM) cluster can send specially crafted messages with unchecked length fields. This can lead to a heap out-of-bounds write, p…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.76%via CSAF
CVE-2026-89587High· 7.0
2w ago

kernel: ACPI: pfr_update: fix stack buffer overflow in query_capability() (CVE-2026-89587)

A flaw was found in the Linux kernel's ACPI Platform Firmware Runtime Update (pfr_update) component. The `query_capability()` function, responsible for handling ACPI buffer objects from firmware, performs an unchecked memory copy operation…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2026-89652High· 7.0⚖ disputed
2w ago

kernel: ceph: bound copied dentry name length in NFS export get_name (CVE-2026-89652)

A flaw was found in the Linux kernel's Ceph file system. A malicious or compromised Ceph Metadata Server (MDS) can send a specially crafted `LOOKUPNAME` reply that causes a buffer overflow when copying dentry names during an NFS export ope…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.67%via CSAF
CVE-2026-48490Medium· 6.9
2w ago

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point…

▾ Sunlitarduino · ArduinoCore-avrEPSS 0.67%via NVD
CVE-2026-89092Medium· 4.2
2w ago

glibc: nscd stack overflow leads to degraded DNS resolution (CVE-2026-89092)

A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, ca…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.27%via CSAF
CVE-2026-88047High· 7.8
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-87931Critical· 9.6
2w ago

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation lead…

▾ MidnightBehavioral Technology Group · Pavlok Behavioral Conditioning WearableEPSS 0.60%via NVD
CVE-2026-42808Medium· 6.8
2w ago

An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Inte…

An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Inte…

▾ SunlitBosch Sensortec · COINES_SDKEPSS 0.27%via NVD
CVE-2026-71612High· 8.4PoC
2w ago

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6.

▾ MidnightEPSS 0.21%via NVD
CVE-2026-87654Critical· 9.6
2w ago

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-58823High· 7.8
2w ago

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CWE-120 vulnerabilities (CVEs) — page 3 · VulnSea