CWE-120
High likelihoodBuffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Parent: CWE-787 - Out-of-bounds Write
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
4,333 vulnerabilities with CWE-120
CVE-2026-28859
MEDIUM
Safari < 26.4 - Out-of-bounds Read
CVSS 4.3
CVE-2026-28858
CRITICAL
iOS and iPadOS < 26.4 - Remote Denial of Service and Memory Corruption via Buffer Overflow
CVSS 9.8
CVE-2026-28857
MEDIUM
Safari < 26.4 - Out-of-bounds Read via Malicious Web Content
CVSS 6.5
CVE-2026-28841
MEDIUM
macOS < 26.4 - Buffer Overflow via Improved Size Validation
CVSS 6.2
CVE-2026-20664
MEDIUM
Safari < 26.4 - Out-of-bounds Write via Malicious Web Content
CVSS 4.3
CVE-2026-27654
HIGH
NGINX ngx_http_dav_module vulnerability
CVSS 8.2
CVE-2026-4729
CRITICAL
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4721
CRITICAL
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4720
CRITICAL
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4690
HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687
HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-30006
MEDIUM
XnSoft NConvert 7.230 - Buffer Overflow
CVSS 6.2
CVE-2026-4565
HIGH
Tenda AC21 SetNetControlList formSetQosBand buffer overflow
CVSS 8.8
CVE-2026-4488
HIGH
UTT HiPER 1250GW setSysAdm strcpy buffer overflow
CVSS 8.8
CVE-2026-4487
HIGH
UTT HiPER 1200GW websHostFilter strcpy buffer overflow
CVSS 8.8
CVE-2026-27459
CRITICAL
pyOpenSSL DTLS cookie callback buffer overflow
CVSS 9.8
CVE-2026-4318
HIGH
UTT HiPER 810G formApLbConfig strcpy buffer overflow
CVSS 8.8
CVE-2026-4177
CRITICAL
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
CVSS 9.1
CVE-2026-4227
HIGH
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
CVSS 8.8
CVE-2026-3082
HIGH
GStreamer - Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-3081
HIGH
GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-32706
HIGH
PX4 autopilot <1.17.0-rc2 - Memory Corruption
CVSS 7.1
CVE-2026-2920
HIGH
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-0849
LOW
Zephyr crypto driver - Buffer Overflow
CVSS 3.8
Details
Vulnerabilities
4,333
Exploit Likelihood
High