CWE-120
High likelihoodBuffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Parent: CWE-787 - Out-of-bounds Write
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
4,199 vulnerabilities with CWE-120
CVE-2025-50402
CRITICAL
FAST FAC1200R F400_FAC1200R_Q - Buffer Overflow via fac_password Parameter
CVSS 9.8
CVE-2025-50399
CRITICAL
FAST FAC1200R F400_FAC1200R_Q - Buffer Overflow via Password Parameter
CVSS 9.8
CVE-2025-9558
HIGH
Zephyr RTOS - Buffer Overflow in pb_adv.c
CVSS 7.6
CVE-2025-9557
HIGH
Zephyr RTOS <= 4.2 - Out-of-Bounds Write
CVSS 7.6
CVE-2025-12970
HIGH
Fluent Bit - Buffer Overflow in Docker Input Plugin Container Name Handling
CVSS 8.8
CVE-2025-13553
HIGH
D-Link DWR-M920 1.1.50 - Buffer Overflow via submit-url Parameter in formPinManageSetup
CVSS 8.8
CVE-2025-13552
HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Parameter
CVSS 8.8
CVE-2025-13551
HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Parameter
CVSS 8.8
CVE-2025-13550
HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via VPN Config Setup submit-url Parameter
CVSS 8.8
CVE-2025-13549
HIGH
D-Link DIR-822K 1.00 - Buffer Overflow via NTP Submit-URL Parameter
CVSS 8.8
CVE-2025-13548
HIGH
D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50 - Buffer Overflow via submit-url Argument
CVSS 8.8
CVE-2025-65102
HIGH
pjproject < 2.16 - Memory Corruption via Opus PLC Frame Handling
CVE-2025-65226
MEDIUM
Tenda AC21 V16.03.08.16 - Buffer Overflow via deviceId Parameter
CVSS 4.3
CVE-2025-13400
HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via chkHz Argument in WrlExtraGet Function
CVSS 8.8
CVE-2025-46776
MEDIUM
Fortinet FortiExtender <7.6.1 - Buffer Overflow
CVSS 6.4
CVE-2025-36553
HIGH
Dell ControlVault3 <5.15.14.19 - Buffer Overflow
CVSS 8.8
CVE-2025-32089
HIGH
Dell ControlVault3 <5.15.14.19 - Dell ControlVault3 Plus <6.2.36.47...
CVSS 8.8
CVE-2025-13305
HIGH
D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K, and DIR-825M 1.01.07 - Buffer Overflow via Traceroute Host Parameter
CVSS 8.8
CVE-2025-13304
HIGH
D-Link DWR-M920/M921/M960/M961 & DIR-825M 1.01.07/1.1.47 - Buffer Overflow via Ping Host Argument
CVSS 8.8
CVE-2025-13288
HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via PPTPUserSetting delno Parameter
CVSS 8.8
CVE-2025-13258
HIGH
Tenda AC20 <= 16.03.08.12 - Buffer Overflow via WifiExtraSet wpapsk_crypto Argument
CVSS 8.8
CVE-2025-63679
HIGH
free5gc < 4.1.0 - Buffer Overflow via UplinkRANConfigurationTransfer NGAP Message
CVSS 7.5
CVE-2025-40815
HIGH
Siemens LOGO! and SIPLUS LOGO! - Buffer Overflow via TCP Packet Structure Validation
CVSS 7.2
CVE-2025-32732
MEDIUM
Intel QuickAssist Technology < 2.6.0-0018 - Denial of Service via Buffer Overflow
CVSS 6.6
CVE-2025-24519
MEDIUM
Intel QuickAssist Technology < 2.6.0-0018 - Authenticated Buffer Overflow in Ring 3
CVSS 6.5
Details
Vulnerabilities
4,199
Exploit Likelihood
High