CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,333 vulnerabilities with CWE-120
CVE-2026-28859 MEDIUM
Safari < 26.4 - Out-of-bounds Read
CVSS 4.3
CVE-2026-28858 CRITICAL
iOS and iPadOS < 26.4 - Remote Denial of Service and Memory Corruption via Buffer Overflow
CVSS 9.8
CVE-2026-28857 MEDIUM
Safari < 26.4 - Out-of-bounds Read via Malicious Web Content
CVSS 6.5
CVE-2026-28841 MEDIUM
macOS < 26.4 - Buffer Overflow via Improved Size Validation
CVSS 6.2
CVE-2026-20664 MEDIUM
Safari < 26.4 - Out-of-bounds Write via Malicious Web Content
CVSS 4.3
CVE-2026-27654 HIGH
NGINX ngx_http_dav_module vulnerability
CVSS 8.2
CVE-2026-4729 CRITICAL
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4721 CRITICAL
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4720 CRITICAL
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4690 HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689 CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687 HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-30006 MEDIUM
XnSoft NConvert 7.230 - Buffer Overflow
CVSS 6.2
CVE-2026-4565 HIGH
Tenda AC21 SetNetControlList formSetQosBand buffer overflow
CVSS 8.8
CVE-2026-4488 HIGH
UTT HiPER 1250GW setSysAdm strcpy buffer overflow
CVSS 8.8
CVE-2026-4487 HIGH
UTT HiPER 1200GW websHostFilter strcpy buffer overflow
CVSS 8.8
CVE-2026-27459 CRITICAL
pyOpenSSL DTLS cookie callback buffer overflow
CVSS 9.8
CVE-2026-4318 HIGH
UTT HiPER 810G formApLbConfig strcpy buffer overflow
CVSS 8.8
CVE-2026-4177 CRITICAL
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
CVSS 9.1
CVE-2026-4227 HIGH
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
CVSS 8.8
CVE-2026-3082 HIGH
GStreamer - Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-3081 HIGH
GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-32706 HIGH
PX4 autopilot <1.17.0-rc2 - Memory Corruption
CVSS 7.1
CVE-2026-2920 HIGH
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-0849 LOW
Zephyr crypto driver - Buffer Overflow
CVSS 3.8
Details
Vulnerabilities 4,333
Exploit Likelihood High