1767 vulnerabilities classified as CWE-120 (未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)). AI Chinese analysis included.
CWE-120 represents a critical memory safety vulnerability where software copies data into a fixed-size buffer without validating the input’s length against the destination’s capacity. This classic buffer overflow occurs when an attacker supplies input exceeding the allocated memory space, causing data to spill into adjacent memory regions. Exploitation typically involves injecting malicious code or altering program control flow, such as overwriting return addresses to execute arbitrary commands. Developers prevent this weakness by implementing rigorous bounds checking before any copy operation, ensuring the input size never exceeds the buffer’s limits. Utilizing safer, language-specific functions that automatically handle size verification, or adopting modern programming languages with built-in memory safety features, effectively mitigates this risk and preserves application integrity against memory corruption attacks.
char last_name[20]; printf ("Enter your last name: "); scanf ("%s", last_name);void manipulate_string(char * string){ char buf[24]; strcpy(buf, string); ... }| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-43970 | Buffer overflow in Linksys WRT54GL — WRT54GL Wireless-G Broadband Router | 7.2 | High | 2023-01-09 |
| CVE-2022-39118 | UNISOC chipset 缓冲区错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-4857 | Modbus Tools Modbus Poll mbp File mbpoll.exe buffer overflow — Modbus Poll | 6.3 | Medium | 2022-12-30 |
| CVE-2022-4856 | Modbus Tools Modbus Slave mbs File mbslave.exe buffer overflow — Modbus Slave | 6.3 | Medium | 2022-12-30 |
| CVE-2022-42261 | NVIDIA vGPU Software 安全漏洞 — vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) | 7.8 | High | 2022-12-30 |
| CVE-2022-41966 | XStream Denial of Service via stack overflow — xstream | 8.2 | High | 2022-12-27 |
| CVE-2022-23477 | Buffer Overflow in xrdp — xrdp | 9.1 | Critical | 2022-12-09 |
| CVE-2022-23480 | Buffer Overflow in xrdp — xrdp | 9.1 | Critical | 2022-12-09 |
| CVE-2022-23479 | Buffer Overflow occurs in xrdp — xrdp | 9.1 | Critical | 2022-12-09 |
| CVE-2022-23468 | Buffer Overflow in xrdp — xrdp | 6.5 | Medium | 2022-12-09 |
| CVE-2022-46824 | JetBrains IntelliJ IDEA 安全漏洞 — IntelliJ IDEA | 5.6 | Medium | 2022-12-08 |
| CVE-2022-41802 | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. — OpenHarmony | 4.0 | Medium | 2022-12-08 |
| CVE-2022-44455 | The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. — OpenHarmony | 6.8 | Medium | 2022-12-08 |
| CVE-2022-20687 | Cisco ATA 190 输入验证错误漏洞 — Cisco Analog Telephone Adaptor (ATA) Software | 5.3 | Medium | 2022-12-07 |
| CVE-2022-42756 | Google Pixel 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2022-12-06 |
| CVE-2022-42760 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8018 | 5.5 | - | 2022-12-06 |
| CVE-2022-4172 | QEMU 安全漏洞 — QEMU (ACPI ERST) | 6.5 | - | 2022-11-29 |
| CVE-2022-41894 | Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite — tensorflow | 7.1 | High | 2022-11-18 |
| CVE-2022-0324 | Buffer Overflow in Dhcp6relay in Software for Open Networking in the Cloud (SONiC) — Software for Open Networking in the Cloud (SONiC) | 8.1 | High | 2022-11-14 |
| CVE-2022-20927 | Cisco Firepower Threat Defense和Cisco Adaptive Security Appliances Software 缓冲区错误漏洞 — Cisco Adaptive Security Appliance (ASA) Software | 7.7 | High | 2022-11-10 |
| CVE-2021-34566 | WAGO I/O-Check Service prone to Memory Overflow — 750-81xx/xxx-xxxFW | 9.1 | Critical | 2022-11-09 |
| CVE-2022-39343 | Azure RTOS FileX vulnerable to Buffer Offerflow — filex | 5.6 | Medium | 2022-11-08 |
| CVE-2022-39344 | Azure RTOS USBX vulnerable to buffer overflow — usbx | 9.8 | Critical | 2022-11-04 |
| CVE-2022-23462 | Stack Buffer Overflow in iowow — iowow | 6.2 | Medium | 2022-10-21 |
| CVE-2022-39120 | UNISOC chipset 缓冲区错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2022-10-14 |
| CVE-2022-39121 | UNISOC chipset 缓冲区错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2022-10-14 |
| CVE-2022-39122 | UNISOC chipset 缓冲区错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2022-10-14 |
| CVE-2022-36361 | Siemens LOGO! 8 BM 安全漏洞 — LOGO! 12/24RCE | 9.8 | Critical | 2022-10-11 |
| CVE-2022-39244 | Buffer overflow in pjlib scanner and pjmedia — pjproject | 7.5 | High | 2022-10-06 |
| CVE-2022-39274 | Buffer Overflow in `ProcessRadioRxDone` in LoRaMac-node — LoRaMac-node | 7.5 | High | 2022-10-06 |
Vulnerabilities classified as CWE-120 (未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)) represent 1767 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.