CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,960 vulnerabilities with CWE-119
CVE-2025-15356 HIGH
Tenda AC20 Firmware <= 16.03.08.12 - Buffer Overflow via PowerSaveSet sscanf Argument
CVSS 8.8
CVE-2025-15255 CRITICAL
Tenda W6-S 1.0.0.4(510) - Stack-Based Buffer Overflow via Cookie Argument
CVSS 9.8
CVE-2025-15253 HIGH
Tenda M3 1.0.0.13(4903) - Stack-Based Buffer Overflow via /goform/exeCommand cmdinput Argument
CVSS 8.8
CVE-2025-15252 HIGH
Tenda M3 1.0.0.13(4903) - Stack-Based Buffer Overflow via formSetRemoteDhcpForAp
CVSS 8.8
CVE-2025-15247 HIGH
gmg137 snap7-rs - Heap-Based Buffer Overflow in S7Client::download Function
CVSS 7.3
CVE-2025-15234 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via formSetRemoteInternetLanInfo
CVSS 8.8
CVE-2025-15233 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via formSetAdInfoDetails
CVSS 8.8
CVE-2025-15232 HIGH
Tenda M3 1.0.0.13(4903) - Stack-based Buffer Overflow via setAdPushInfo mac/terminal Parameter
CVSS 8.8
CVE-2025-15231 HIGH
Tenda M3 1.0.0.13(4903) - Stack-based Buffer Overflow via setVlanInfo ID/vlan/port Argument
CVSS 8.8
CVE-2025-15230 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via qvlan_truck_port Parameter
CVSS 8.8
CVE-2025-15218 HIGH
Tenda AC10U 15.03.06.48/15.03.06.49 - Buffer Overflow via lanMask Parameter in fromadvsetlanip
CVSS 8.8
CVE-2025-15217 HIGH
Tenda AC23 16.03.07.52 - Buffer Overflow via formSetPPTPUserList HTTP POST Argument
CVSS 8.8
CVE-2025-15216 HIGH
Tenda AC23 16.03.07.52 - Stack-based Buffer Overflow via SetIpMacBind bindnum Argument
CVSS 8.8
CVE-2025-15215 HIGH
Tenda AC10U 15.03.06.48/15.03.06.49 - Buffer Overflow via setPptpUserList HTTP POST Request
CVSS 8.8
CVE-2025-15194 CRITICAL
D-Link DIR-600 up to 2.15WWb02 - Stack-Based Buffer Overflow via Cookie Argument in hedwig.cgi
CVSS 9.8
CVE-2025-15193 HIGH
D-Link DWR-M920 < 1.1.50 - Buffer Overflow via formParentControl submit-url Argument
CVSS 8.8
CVE-2025-15190 HIGH
D-Link DWR-M920 < 1.1.50 - Stack-Based Buffer Overflow via formFilter ip6addr Argument
CVSS 8.8
CVE-2025-15189 HIGH
D-Link DWR-M920 < 1.1.50 - Buffer Overflow via formDefRoute submit-url Parameter
CVSS 8.8
CVE-2025-15180 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via webExcptypemanFilte Page Argument
CVSS 7.2
CVE-2025-15179 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via qossetting Page Parameter
CVSS 7.2
CVE-2025-15178 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via VirtualSer Page Parameter
CVSS 7.2
CVE-2025-15177 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via SetIpBind HTTP Request Handler
CVSS 7.2
CVE-2025-15164 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via SafeMacFilter Page Parameter
CVSS 7.2
CVE-2025-15163 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via SafeEmailFilter Page Parameter
CVSS 7.2
CVE-2025-15162 HIGH
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via RouteStatic Page Parameter
CVSS 7.2
Details
Vulnerabilities 13,960
Exploit Likelihood High