Classic Buffer Overflow

CWE-120 · 8 records · 4 with a public proof-of-concept

Records the NVD classes as Classic Buffer Overflow (CWE-120), highest CVSS first.

  1. CRITICAL 9.1CVE-2026-45537public PoC

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buff

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-45100public PoC

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the input fits wit

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.8CVE-2026-24080

    Memory Corruption when handling malformed request parameters in the fingerprint TA.

    qam8295p firmware · qam8295p · qca6574au firmware · qca6574au · qca6595au firmware · qca6595au

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-67859public PoC

    Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-67858public PoC

    Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containin

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-15314

    Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing th

    tapo p110 firmware · tapo p110

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.7CVE-2026-24076

    Memory Corruption when processing registry values with incorrect types using a direct query method.

    aqt1000 firmware · aqt1000 · cologne firmware · cologne · fastconnect 6200 firmware · fastconnect 6200

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.9CVE-2026-18103

    A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease c

    AI risk analysis on Exploit-DB.ai →