CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2025-6494 LOW
Nokogiri - Heap-Based Buffer Overflow in hashmap_get_with_hash
CVSS 3.3
CVE-2025-6490 LOW
Nokogiri - Heap-Based Buffer Overflow in hashmap_set_with_hash
CVSS 3.3
CVE-2025-6487 HIGH
TOTOLINK A3002R 1.1.1-B20200824.0128 - Stack-Based Buffer Overflow in formRoute
CVSS 8.8
CVE-2025-6486 HIGH
TOTOLINK A3002R 1.1.1-B20200824.0128 - Stack-Based Buffer Overflow in formWlanMultipleAP
CVSS 8.8
CVE-2025-6402 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
CVSS 8.8
CVE-2025-6400 HIGH
TOTOLINK N300RH 6.1c.1390_B20191101 - Buffer Overflow via HTTP POST Message Handler
CVSS 8.8
CVE-2025-6399 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via IPv6 Address Handler
CVSS 8.8
CVE-2025-6393 HIGH
TOTOLINK A702R A3002R A3002RU EX1200T - Buffer Overflow via IPv6 Address Handler
CVSS 8.8
CVE-2025-6374 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow in formSetACLFilter
CVSS 8.8
CVE-2025-6373 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via curTime Parameter in formSetWizard1
CVSS 8.8
CVE-2025-6372 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via curTime Parameter in formSetWizard1
CVSS 8.8
CVE-2025-6371 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via curTime Parameter in formSetEnableWizard
CVSS 8.8
CVE-2025-6370 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow in formWlanGuestSetup
CVSS 8.8
CVE-2025-6369 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via curTime/config.save_network_enabled
CVSS 8.8
CVE-2025-6368 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via formSetEmail curTime Parameter
CVSS 8.8
CVE-2025-6367 HIGH
D-Link DIR-619L 2.06B01 - Stack-Based Buffer Overflow via curTime/sched_name_%d/url_%d Parameters
CVSS 8.8
CVE-2025-6337 HIGH
TOTOLINK A3002R/A3002RU <4.0.0-B20230531.1404 - Buffer Overflow
CVSS 8.8
CVE-2025-6336 HIGH
TOTOLINK EX1200T 4.1.2cu.5232_B20210713 - Buffer Overflow
CVSS 8.8
CVE-2025-6334 HIGH
D-Link DIR-867 1.0 - Buffer Overflow
CVSS 8.8
CVE-2025-6328 HIGH
D-Link DIR-815 1.01 - Buffer Overflow
CVSS 8.8
CVE-2025-6302 HIGH
TOTOLINK EX1200T 4.1.2cu.5232_B20210713 - Buffer Overflow
CVSS 8.8
CVE-2025-6292 HIGH
D-Link DIR-825 2.03 - Buffer Overflow
CVSS 8.8
CVE-2025-6291 HIGH
D-Link DIR-825 2.03 - Buffer Overflow
CVSS 8.8
CVE-2025-6275 LOW
WebAssembly wabt <1.0.37 - Use After Free
CVSS 3.3
CVE-2025-6272 LOW
wasm3 0.5.0 - Out-of-Bounds Write in MarkSlotAllocated
CVSS 3.3
Details
Vulnerabilities 13,962
Exploit Likelihood High