CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,732 vulnerabilities with CWE-119
CVE-2026-5185 MEDIUM
Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow
CVSS 5.3
CVE-2026-5156 HIGH
Tenda CH22 Parameter QuickIndex formQuickIndex stack-based overflow
CVSS 8.8
CVE-2026-5155 HIGH
Tenda CH22 Parameter AdvSetWan fromAdvSetWan stack-based overflow
CVSS 8.8
CVE-2026-5154 HIGH
Tenda CH22 Parameter setcfm fromSetCfm stack-based overflow
CVSS 8.8
CVE-2026-5152 HIGH
Tenda CH22 createFileName formCreateFileName stack-based overflow
CVSS 8.8
CVE-2026-5046 HIGH
Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow
CVSS 8.8
CVE-2026-5045 HIGH
Tenda FH1201 Parameter WrlclientSet stack-based overflow
CVSS 8.8
CVE-2026-5044 HIGH
Belkin F9K1122 Setting formSetSystemSettings stack-based overflow
CVSS 8.8
CVE-2026-5043 HIGH
Belkin F9K1122 Parameter formSetPassword stack-based overflow
CVSS 8.8
CVE-2026-5042 HIGH
Belkin F9K1122 Parameter formCrossBandSwitch stack-based overflow
CVSS 8.8
CVE-2026-5037 LOW
mxml mxmlIndexNew mxml-index.c index_sort stack-based overflow
CVSS 3.3
CVE-2026-5036 HIGH
Tenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow
CVSS 8.8
CVE-2026-5024 HIGH
D-Link DIR-513 formSetEmail stack-based overflow
CVSS 8.8
CVE-2026-5021 HIGH
Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow
CVSS 8.8
CVE-2026-5004 HIGH
Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow
CVSS 8.8
CVE-2026-4976 HIGH
Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
CVSS 8.8
CVE-2026-4975 HIGH
Tenda AC15 POST Request setcfm formSetCfm memory corruption
CVSS 8.8
CVE-2026-4974 HIGH
Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption
CVSS 8.8
CVE-2026-4961 HIGH
Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow
CVSS 8.8
CVE-2026-4960 HIGH
Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow
CVSS 8.8
CVE-2026-4906 HIGH
Tenda AC5 POST Request WizardHandle decodePwd stack-based overflow
CVSS 8.8
CVE-2026-4905 HIGH
Tenda AC5 POST Request WifiWpsOOB formWifiWpsOOB stack-based overflow
CVSS 8.8
CVE-2026-4904 HIGH
Tenda AC5 POST Request setcfm formSetCfm stack-based overflow
CVSS 8.8
CVE-2026-4903 HIGH
Tenda AC5 POST Request QuickIndex formQuickIndex memory corruption
CVSS 8.8
CVE-2026-4902 HIGH
Tenda AC5 POST Request addressNat fromAddressNat memory corruption
CVSS 8.8
Details
Vulnerabilities 13,732
Exploit Likelihood High