CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2025-10756 HIGH
UTT HiPER 840G < 3.1.1-190328 - Buffer Overflow via getOneApConfTempEntry tempName Parameter
CVSS 8.8
CVE-2025-26503 MEDIUM
VxWorks 7 System Call - Memory Corruption
CVSS 6.7
CVE-2025-10666 HIGH
D-Link DIR-825 Firmware < 2.10 - Buffer Overflow via apply.cgi countdown_time Argument
CVSS 8.8
CVE-2025-8001 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing
CVSS 7.8
CVE-2025-10537 HIGH
Firefox and Thunderbird < 143 - Memory Corruption
CVSS 8.8
CVE-2025-43343 CRITICAL
Safari < 26.0 - Memory Corruption via Malicious Web Content
CVSS 9.8
CVE-2025-43287 HIGH
macOS Tahoe <26 - Memory Corruption
CVSS 7.1
CVE-2025-43272 MEDIUM
Safari < 26.0 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2025-10443 HIGH
Tenda AC9 and AC15 15.03.05.14/15.03.05.18 - Buffer Overflow via formexeCommand
CVSS 8.8
CVE-2025-10432 CRITICAL
Tenda AC1206 15.03.06.23 - Stack-Based Buffer Overflow via wanMTU Parameter
CVSS 9.8
CVE-2025-10392 CRITICAL
Mercury KM08-708H GiGA WiFi Wave2 1.1.14 - Buffer Overflow
CVSS 9.8
CVE-2025-10385 HIGH
Mercury KM08-708H GiGA WiFi Wave2 1.1 - Buffer Overflow
CVSS 8.8
CVE-2025-10225 HIGH
AxxonSoft Axxon One < 2.0.6 - Denial of Service via OpenSSL Session Key Reallocation
CVSS 7.5
CVE-2025-58750 HIGH
rAthena <commit 0cc348b - Memory Corruption
CVSS 8.2
CVE-2025-10172 HIGH
UTT 750W Firmware < 3.2.2-191225 - Buffer Overflow via formPictureUrl importpictureurl Parameter
CVSS 8.8
CVE-2025-10171 HIGH
UTT 1250GW Firmware < 3.2.2-200710 - Buffer Overflow in formConfigApConfTemp
CVSS 8.8
CVE-2025-10170 HIGH
UTT 1200GW Firmware < 3.0.0-170831 - Buffer Overflow via loadBalanceNameOld Argument
CVSS 8.8
CVE-2025-10169 HIGH
UTT 1200GW Firmware < 3.0.0-170831 - Buffer Overflow via ConfigWirelessBase SSID Parameter
CVSS 8.8
CVE-2025-10120 HIGH
Tenda AC20 Firmware < 16.03.08.12 - Buffer Overflow via Parent Control MAC Parameter
CVSS 8.8
CVE-2025-10034 HIGH
D-Link DIR-825 1.08.01 - Buffer Overflow in ping6_response.cg via ping6_ipaddr
CVSS 8.8
CVE-2025-9938 HIGH
D-Link DI-8400 16.07.26A1 - Stack-Based Buffer Overflow via yyxz.asp ID Parameter
CVSS 8.8
CVE-2025-9813 HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via samba_userNameSda Parameter
CVSS 8.8
CVE-2025-9812 HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via formexeCommand cmdinput Argument
CVSS 8.8
CVE-2025-9791 HIGH
Tenda AC20 16.03.08.05 - Stack-Based Buffer Overflow via wanMTU Parameter
CVSS 8.8
CVE-2025-9783 HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via Parent Control Form Submit-URL
CVSS 8.8
Details
Vulnerabilities 13,962
Exploit Likelihood High