Vulnerabilities (CVE)

Filtered by CWE-120
Total 4474 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27065 1 Tenda 2 W15e, W15e Firmware 2026-06-17 N/A 7.5 HIGH
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2023-27064 1 Tenda 2 W15e, W15e Firmware 2026-06-17 N/A 7.5 HIGH
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2023-27063 1 Tenda 2 W15e, W15e Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2023-27062 1 Tenda 2 W15e, W15e Firmware 2026-06-17 N/A 7.5 HIGH
Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2023-27061 1 Tenda 2 W15e, W15e Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2023-26966 1 Libtiff 1 Libtiff 2026-06-17 N/A 5.5 MEDIUM
libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
CVE-2023-26930 1 Xpdfreader 1 Xpdf 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”
CVE-2023-26924 1 Llvm 1 Llvm 2026-06-17 N/A 5.5 MEDIUM
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior."
CVE-2023-26768 1 Liblouis 1 Liblouis 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions.
CVE-2023-26767 1 Liblouis 1 Liblouis 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint.
CVE-2023-26733 1 Tinytiff Project 1 Tinytiff 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file.
CVE-2023-26616 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
CVE-2023-26612 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
CVE-2023-26320 1 Mi 2 Xiaomi Router Ax3200, Xiaomi Router Ax3200 Firmware 2026-06-17 N/A 7.5 HIGH
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
CVE-2023-26319 1 Mi 2 Xiaomi Router Ax3200, Xiaomi Router Ax3200 Firmware 2026-06-17 N/A 6.7 MEDIUM
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
CVE-2023-26318 1 Mi 2 Xiaomi Router Ax3200, Xiaomi Router Ax3200 Firmware 2026-06-17 N/A 6.7 MEDIUM
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.
CVE-2023-26110 1 Node-bluetooth Project 1 Node-bluetooth 2026-06-17 N/A 7.3 HIGH
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-26109 1 Node-bluetooth-serial-port Project 1 Node-bluetooth-serial-port 2026-06-17 N/A 7.3 HIGH
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-26076 1 Samsung 10 Exynos 1280, Exynos 1280 Firmware, Exynos 2200 and 7 more 2026-06-17 N/A 7.6 HIGH
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options.
CVE-2023-26075 1 Samsung 18 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 15 more 2026-06-17 N/A 7.6 HIGH
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Service Area List.