CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,199 vulnerabilities with CWE-120
CVE-2025-46108 CRITICAL
D-link Dir-513 A1FW110 - Buffer Overflow
CVSS 9.8
CVE-2025-12345 HIGH
LLM-Claw 0.1.0-0.1.1a-p1 - Buffer Overflow
CVSS 8.8
CVE-2025-61147 MEDIUM
strukturag libde265 d9fea9d - Memory Corruption
CVSS 6.2
CVE-2025-69674 MEDIUM
CDATA FD614GS3-R850 V3.2.7 - Buffer Overflow
CVSS 6.4
CVE-2025-33130 MEDIUM
IBM DB2 Merge Backup 12.1.0.0 - Buffer Overflow
CVSS 6.5
CVE-2025-70314 CRITICAL
webfsd 1.21 - Buffer Overflow via Crafted Request
CVSS 9.8
CVE-2025-69807 HIGH
p2r3 Bareiron - Unauthenticated Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2025-52870 HIGH
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Heap-based Buffer Overflow
CVSS 8.1
CVE-2025-52869 HIGH
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Heap-based Buffer Overflow
CVSS 8.1
CVE-2025-52868 HIGH
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Heap-based Buffer Overflow
CVSS 8.1
CVE-2025-48725 HIGH
QNAP QTS and QuTS hero - Authenticated Buffer Overflow
CVSS 8.1
CVE-2025-48724 HIGH
Qsync Central <5.0.0.4 - Buffer Overflow
CVSS 8.1
CVE-2025-48723 HIGH
Qsync Central <5.0.0.4 - Buffer Overflow
CVSS 8.1
CVE-2025-67189 MEDIUM
TOTOLINK A950RG V4.1.2cu.5204_B20210112 - Buffer Overflow via setParentalRules urlKeyword Parameter
CVSS 6.5
CVE-2025-67188 CRITICAL
TOTOLINK A950RG V4.1.2cu.5204_B20210112 - Buffer Overflow in setRadvdCfg radvdinterfacename Parameter
CVSS 9.8
CVE-2025-67186 CRITICAL
TOTOLINK A950RG V4.1.2cu.5204_B20210112 - Buffer Overflow in setUrlFilterRules Interface
CVSS 9.8
CVE-2025-47399 HIGH
Qualcomm Cologne Firmware - Memory Corruption via IOCTL Sensor Property Update
CVSS 7.8
CVE-2025-14911 MEDIUM
Mongo-c-driver < 2.1.3 - Buffer Overflow via GridFS ChunkSize Metadata
CVSS 6.5
CVE-2025-28164 MEDIUM
libpng 1.6.43-1.6.46 - Denial of Service via png_create_read_struct() Buffer Overflow
CVSS 5.5
CVE-2025-28162 MEDIUM
libpng 1.6.43-1.6.46 - Denial of Service via Buffer Overflow in pngimage
CVSS 5.5
CVE-2025-69209 MEDIUM
ArduinoCore-avr <1.8.7 - Buffer Overflow
CVE-2025-68137 HIGH
EVerest < 2025.10.0 - Infinite Loop via SdpPacket Header Parsing
CVSS 8.3
CVE-2025-55131 HIGH
Node.js 4.0-25.2.0 - Uninitialized Memory Exposure via Buffer Allocation Interruption
CVSS 7.1
CVE-2025-29329 CRITICAL
Sagemcom F@st 3686 Firmware - Remote Code Execution via ippprint Buffer Overflow
CVSS 9.8
CVE-2025-69260 HIGH
Trend Micro Apex Central - Unauthenticated Denial of Service via Message Out-of-Bounds Read
CVSS 7.5
Details
Vulnerabilities 4,199
Exploit Likelihood High