CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,199 vulnerabilities with CWE-120
CVE-2025-50402 CRITICAL
FAST FAC1200R F400_FAC1200R_Q - Buffer Overflow via fac_password Parameter
CVSS 9.8
CVE-2025-50399 CRITICAL
FAST FAC1200R F400_FAC1200R_Q - Buffer Overflow via Password Parameter
CVSS 9.8
CVE-2025-9558 HIGH
Zephyr RTOS - Buffer Overflow in pb_adv.c
CVSS 7.6
CVE-2025-9557 HIGH
Zephyr RTOS <= 4.2 - Out-of-Bounds Write
CVSS 7.6
CVE-2025-12970 HIGH
Fluent Bit - Buffer Overflow in Docker Input Plugin Container Name Handling
CVSS 8.8
CVE-2025-13553 HIGH
D-Link DWR-M920 1.1.50 - Buffer Overflow via submit-url Parameter in formPinManageSetup
CVSS 8.8
CVE-2025-13552 HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Parameter
CVSS 8.8
CVE-2025-13551 HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Parameter
CVSS 8.8
CVE-2025-13550 HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via VPN Config Setup submit-url Parameter
CVSS 8.8
CVE-2025-13549 HIGH
D-Link DIR-822K 1.00 - Buffer Overflow via NTP Submit-URL Parameter
CVSS 8.8
CVE-2025-13548 HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Argument
CVSS 8.8
CVE-2025-65102 HIGH
pjproject < 2.16 - Memory Corruption via Opus PLC Frame Handling
CVE-2025-65226 MEDIUM
Tenda AC21 V16.03.08.16 - Buffer Overflow via deviceId Parameter
CVSS 4.3
CVE-2025-13400 HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via chkHz Argument in WrlExtraGet Function
CVSS 8.8
CVE-2025-46776 MEDIUM
Fortinet FortiExtender <7.6.1 - Buffer Overflow
CVSS 6.4
CVE-2025-36553 HIGH
Dell ControlVault3 <5.15.14.19 - Buffer Overflow
CVSS 8.8
CVE-2025-32089 HIGH
Dell ControlVault3 <5.15.14.19 - Dell ControlVault3 Plus <6.2.36.47...
CVSS 8.8
CVE-2025-13305 HIGH
D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K, and DIR-825M 1.01.07 - Buffer Overflow via Traceroute Host Parameter
CVSS 8.8
CVE-2025-13304 HIGH
D-Link DWR-M920/M921/M960/M961 & DIR-825M 1.01.07/1.1.47 - Buffer Overflow via Ping Host Argument
CVSS 8.8
CVE-2025-13288 HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via PPTPUserSetting delno Parameter
CVSS 8.8
CVE-2025-13258 HIGH
Tenda AC20 <= 16.03.08.12 - Buffer Overflow via WifiExtraSet wpapsk_crypto Argument
CVSS 8.8
CVE-2025-63679 HIGH
free5gc < 4.1.0 - Buffer Overflow via UplinkRANConfigurationTransfer NGAP Message
CVSS 7.5
CVE-2025-40815 HIGH
Siemens LOGO! and SIPLUS LOGO! - Buffer Overflow via TCP Packet Structure Validation
CVSS 7.2
CVE-2025-32732 MEDIUM
Intel QuickAssist Technology < 2.6.0-0018 - Denial of Service via Buffer Overflow
CVSS 6.6
CVE-2025-24519 MEDIUM
Intel QuickAssist Technology < 2.6.0-0018 - Authenticated Buffer Overflow in Ring 3
CVSS 6.5
Details
Vulnerabilities 4,199
Exploit Likelihood High