CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,198 vulnerabilities with CWE-120
CVE-2026-12192 HIGH
GALAYOU Y4 Web Server buffer overflow
CVSS 8.8
CVE-2026-36818 HIGH
Tenda W20E 15.11.0.6 - Denial of Service via wewifiWhiteUserInfo Buffer Overflow
CVSS 7.5
CVE-2026-36817 HIGH
Tenda W15E 15.11.0.10 - Buffer Overflow in formAddWebAuthWhiteUser
CVSS 7.5
CVE-2026-36816 HIGH
Tenda W15E v15.11.0.10 - Buffer Overflow in wewifiWhiteUserInfo Parameter
CVSS 7.5
CVE-2026-36815 HIGH
Tenda W15E 15.11.0.10 - Denial of Service via Hostname Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36811 HIGH
Tenda W15E 15.11.0.10 - Denial of Service via formDelwebAuthPic picName Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36810 HIGH
Tenda W15E 15.11.0.10 - Denial of Service via Buffer Overflow in formPortalAuth gotoUrl Parameter
CVSS 7.5
CVE-2026-36809 HIGH
Tenda W15E 15.11.0.10 - Denial of Service via webAuthWhiteID Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36808 HIGH
Tenda W15E v15.11.0.10 - Denial of Service via webAuthUserInfo Buffer Overflow
CVSS 7.5
CVE-2026-36807 HIGH
Tenda W15E 15.11.0.10 - Denial of Service via formAddWebAuthUser webAuthUserPwd Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36803 HIGH
Tenda PW201A v1.0.5 - Buffer Overflow in qossetting Page Parameter
CVSS 7.5
CVE-2026-36802 HIGH
Tenda PW201A v1.0.5 - Denial of Service via SafeMacFilter Page Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36801 HIGH
Tenda G0 15.11.0.5 - Denial of Service via IPMacBindRule Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36800 HIGH
Tenda G0 v15.11.0.5 - Buffer Overflow in formIPMacBindDel IPMacBindIndex Parameter
CVSS 7.5
CVE-2026-36799 HIGH
Tenda G0 v15.11.0.5 - Denial of Service via PortalAuth Parameter Buffer Overflow
CVSS 7.5
CVE-2026-36797 HIGH
Tenda G0 v15.11.0.5 - Denial of Service via IPMacBindRuleIp Parameter Overflow
CVSS 7.5
CVE-2026-36796 HIGH
Tenda G0 15.11.0.5 - Denial of Service via picCropName Parameter Stack Overflow
CVSS 7.5
CVE-2026-30141 CRITICAL
bitbank2 AnimatedGIF 2.2.0 - Buffer Overflow in DecodeLZW Function
CVSS 9.8
CVE-2026-11517 HIGH
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
CVSS 8.8
CVE-2026-11516 MEDIUM
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow
CVSS 5.5
CVE-2026-30652 HIGH
Vivotek FD8136 FD8136-VVTK-0300a - Authenticated Remote Code Execution via setdo.cgi Buffer Overflow
CVSS 8.8
CVE-2026-30650 HIGH
Vivotek FD8136 FD8136-VVTK-0300a - Authenticated Remote Buffer Overflow in Event Task CGI
CVSS 8.8
CVE-2026-3871 MEDIUM
Zyxel VMG4005-B50B Firmware - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS 6.5
CVE-2026-3870 MEDIUM
Zyxel VMG4005-B50B Firmware - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS 6.5
CVE-2026-25277 HIGH
Qualcomm Snapdragon Secure Processor - Strongbox Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 4,198
Exploit Likelihood High