CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,334 vulnerabilities with CWE-120
CVE-2026-52196 HIGH
UTT nv518G nv518GV3v3.2.7-210919-161313 - Buffer Overflow via gohead/sub_416f28
CVSS 7.5
CVE-2026-13583 HIGH
Edimax EW-7478APC POST Request formUSBFolder buffer overflow
CVSS 8.8
CVE-2026-13582 HIGH
Edimax EW-7478APC POST Request formUSBAccount buffer overflow
CVSS 8.8
CVE-2026-13580 HIGH
Edimax EW-7478APC POST Request formQoS buffer overflow
CVSS 8.8
CVE-2026-13562 HIGH
Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow
CVSS 8.8
CVE-2026-48706 MEDIUM
Envoy Heap Buffer Overflow in TcpStatsdSink
CVSS 5.9
CVE-2026-57874 HIGH
GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)
CVSS 7.5
CVE-2026-6681 MEDIUM
PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
CVSS 5.3
CVE-2026-53203 HIGH
accel/ivpu: Add buffer overflow check in MS get_info_ioctl
CVSS 7.1
CVE-2026-12246 HIGH
NLnet Labs NSD < 4.14.3 - APL RR Stack Buffer Overflow
CVSS 8.1
CVE-2026-42450 HIGH
OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser
CVE-2026-54257 CRITICAL
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
CVE-2026-12806 HIGH
Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
CVSS 8.8
CVE-2026-43994 HIGH
Coturn: Stack buffer overflow in decode_oauth_token_gcm()
CVSS 8.1
CVE-2026-38718 HIGH
InHand Networks IR912 and IR915 <= V1.0.0.r20042 - Denial of Service via Device Registration Buffer Overflow
CVSS 7.5
CVE-2026-7300 MEDIUM
Connext Professional 7.*, 7.3.1.3, and 6.1.* - Buffer Overflow
CVSS 6.5
CVE-2026-0165 MEDIUM
Google Android - Information Disclosure
CVSS 5.7
CVE-2026-0164 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0160 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0157 MEDIUM
Google Android - Information Disclosure
CVSS 4.3
CVE-2026-0155 MEDIUM
Google Android - Information Disclosure
CVSS 4.3
CVE-2026-0154 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0147 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0146 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0144 MEDIUM
Google Android - Denial of Service
CVSS 6.5
Details
Vulnerabilities 4,334
Exploit Likelihood High