Skip to main content

CWE archive

CWE-120 CVEs

Programmatic archive

4,327 CVEs tagged with CWE-120890 Critical, 2,253 High, 1,109 Medium, 75 Low, 0 Unrated.

CVE-2026-51252

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-64767

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64722

Published Jul 27, 2026

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a 3D model…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-64691

Published Jul 27, 2026

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43776

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously cr…

CVSS 7.8 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-43750

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute ar…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43681

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A local user may be able to read…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-28981

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-59250

Published Jul 27, 2026

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code…

CVSS 8.3 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-45811

Published Jul 24, 2026

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-63453

Published Jul 21, 2026

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44880

Published Jul 21, 2026

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to ex…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44436

Published Jul 16, 2026

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-32389

Published Jul 16, 2026

Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs comp…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-51380

Published Jul 15, 2026

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cg…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-58553

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58552

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58551

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58550

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58549

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-51808

Published Jul 14, 2026

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 4,327 CVEsPage 1 of 174