CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,199 vulnerabilities with CWE-120
CVE-2025-15189 HIGH
D-Link DWR-M920 < 1.1.50 - Buffer Overflow via formDefRoute submit-url Parameter
CVSS 8.8
CVE-2025-15092 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via ConfigExceptMSN Remark Parameter
CVSS 8.8
CVE-2025-15091 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via formPictureUrl importpictureurl Parameter
CVSS 8.8
CVE-2025-15090 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via timestart Argument in formConfigNoticeConfig
CVSS 8.8
CVE-2025-15089 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via wepkey1 Argument in /goform/APSecurity
CVSS 8.8
CVE-2025-8065 MEDIUM
TP-Link Tapo C200 V3 < V3_1.4.5 & C520WS v2.6 < 1.2.4 - RCE via ONVIF SOAP XML Prefix Overflow
CVSS 6.5
CVE-2025-50681 HIGH
igmpproxy 0.4 - Denial of Service via Crafted IGMPv3 Membership Report Packet
CVSS 7.5
CVE-2025-47372 CRITICAL
Qualcomm Firmware - Memory Corruption via Oversized ELF Image
CVSS 9.0
CVE-2025-47321 HIGH
Qualcomm FastConnect 6200 Firmware - Buffer Overflow via Unix Client Packet Copy
CVSS 7.8
CVE-2025-68114 MEDIUM
Capstone <6.0.0-Alpha5 - Buffer Overflow
CVSS 4.8
CVE-2025-66647 CRITICAL
RIOT OS < 2025.10 - Buffer Overflow in IPv6 Fragmentation Reassembly
CVSS 9.8
CVE-2025-43501 MEDIUM
Safari < 26.2 - Buffer Overflow via Malicious Web Content
CVSS 4.3
CVE-2025-67074 MEDIUM
Tenda AC10V4.0 V16.03.10.20 - Buffer Overflow in fromAdvSetMacMtuWan via serverName Field
CVSS 6.5
CVE-2025-67073 CRITICAL
Tenda AC10V4.0 V16.03.10.20 - Buffer Overflow in fromAdvSetMacMtuWan via serviceName Parameter
CVSS 9.8
CVE-2025-65834 CRITICAL
Meltytech Shotcut 25.10.31 - Buffer Overflow
CVSS 9.8
CVE-2025-50401 CRITICAL
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 - Buffer Overflow via Password Parameter
CVSS 9.8
CVE-2025-50398 CRITICAL
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 - Buffer Overflow via fac_password Parameter
CVSS 9.8
CVE-2025-10889 HIGH
Autodesk Shared Components < 2026.5 and 1.8.0.7-1.9.0.7 - Memory Corruption via CATPART File Parsing
CVSS 7.8
CVE-2025-10887 HIGH
Autodesk Shared Components < 2026.5 and >=1.8.0.7 <1.9.0.7 - Memory Corruption via Malicious MODEL File
CVSS 7.8
CVE-2025-10886 HIGH
Autodesk Shared Components < 2026.5 and >=1.8.0.7 <1.9.0.7 - Memory Corruption via Malicious MODEL File
CVSS 7.8
CVE-2025-59947 CRITICAL
NanoMQ < 0.24.4 - Buffer Overflow via PUBLISH Packet Processing
CVSS 9.0
CVE-2025-14709 CRITICAL
sgwbox N3 < 2.0.25 - Buffer Overflow via WIRELESSCFGGET Interface params Argument
CVSS 9.8
CVE-2025-14708 CRITICAL
sgwbox N3 < 2.0.25 - Buffer Overflow via WIREDCFGGET Interface Params Argument
CVSS 9.8
CVE-2025-14656 HIGH
Tenda AC20 16.03.08.12 - Buffer Overflow
CVSS 8.8
CVE-2025-43532 LOW
macOS < 14.8.3 - Memory Corruption via Bounds Checking Issue
CVSS 2.8
Details
Vulnerabilities 4,199
Exploit Likelihood High