CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,217 vulnerabilities with CWE-120
CVE-2025-4731 HIGH
TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615 - Buffer Overflow via HTTP POST Request Handler
CVSS 8.8
CVE-2025-4730 HIGH
TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615 - Buffer Overflow via devicemac1 Parameter
CVSS 8.8
CVE-2025-44879 HIGH
WS-WN572HP3 V230525 - Buffer Overflow
CVSS 7.5
CVE-2025-46785 MEDIUM
Zoom Workplace Apps for Windows - DoS
CVSS 6.5
CVE-2025-45863 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via macstr Parameter in formMapDelDevice Interface
CVSS 9.8
CVE-2025-45865 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via dnsaddr Parameter in formDhcpv6s Interface
CVSS 9.8
CVE-2025-45861 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via routername Parameter
CVSS 9.8
CVE-2025-45866 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via addrPoolEnd Parameter in formDhcpv6s Interface
CVSS 5.4
CVE-2025-45864 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via addrPoolStart Parameter in formDhcpv6s Interface
CVSS 5.4
CVE-2025-45859 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 - Buffer Overflow via bandstr Parameter in formMapDelDevice Interface
CVSS 5.4
CVE-2025-44175 MEDIUM
Tenda AC10 v4 V16.03.10.13 - Buffer Overflow in GetParentControlInfo
CVSS 5.4
CVE-2025-45779 CRITICAL
Tenda AC10 V1.0re_V15.03.06.46 - Buffer Overflow via formSetPPTPUserList list Parameter
CVSS 9.8
CVE-2025-3496 HIGH
Auma Riester AC1.2 06.00.00-06.09.03 - Unauthenticated Buffer Overflow via Bluetooth or RS-232 Interface
CVSS 7.5
CVE-2025-4497 MEDIUM
Simple Banking System <= 1.0 - Buffer Overflow in Sign In Password Handling
CVSS 5.3
CVE-2025-4496 HIGH
Totolink A3000ru Firmware - Memory Corruption
CVSS 8.8
CVE-2025-4462 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow via formWsc localPin Argument
CVSS 8.8
CVE-2025-4452 HIGH
D-Link DIR-619L 2.04B04 - Buffer Overflow via formSetWizard2 curTime Argument
CVSS 8.8
CVE-2025-4451 HIGH
D-Link DIR-619L 2.04B04 - Buffer Overflow via formSetWAN_Wizard52 curTime Argument
CVSS 8.8
CVE-2025-4450 HIGH
D-Link DIR-619L 2.04B04 - Buffer Overflow via formSetEasy_Wizard curTime Argument
CVSS 8.8
CVE-2025-4449 HIGH
D-Link DIR-619L 2.04B04 - Buffer Overflow via formEasySetupWizard3 wan_connected Argument
CVSS 8.8
CVE-2025-4448 HIGH
D-Link DIR-619L 2.04B04 - Buffer Overflow via formEasySetupWizard curTime Argument
CVSS 8.8
CVE-2025-4446 HIGH
H3C GR-5400AX <100R008 - Buffer Overflow
CVSS 8.0
CVE-2025-4442 HIGH
D-Link DIR-605L 2.13B01 - Buffer Overflow via formSetWAN_Wizard55 curTime Argument
CVSS 8.8
CVE-2025-4441 HIGH
D-Link DIR-605L 2.13B01 - Buffer Overflow via formSetWAN_Wizard534 curTime Argument
CVSS 8.8
CVE-2025-4440 HIGH
H3C GR-1800AX <100R008 - Buffer Overflow
CVSS 8.0
Details
Vulnerabilities 4,217
Exploit Likelihood High