CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,217 vulnerabilities with CWE-120
CVE-2025-4117 MEDIUM
Netgear JWNR2000v2 1.0.0.11 - Buffer Overflow in sub_41A914 via Host Argument
CVSS 5.5
CVE-2025-4116 HIGH
Netgear JWNR2000v2 1.0.0.11 - Buffer Overflow via get_cur_lang_ver Function
CVSS 8.8
CVE-2025-4115 HIGH
Netgear JWNR2000v2 1.0.0.11 - Buffer Overflow in default_version_is_new Function
CVSS 8.8
CVE-2025-4114 HIGH
Netgear JWNR2000v2 1.0.0.11 - Buffer Overflow via check_language_file Function
CVSS 8.8
CVE-2025-4079 HIGH
PCMan FTP Server <= 2.0.7 - Buffer Overflow in RENAME Command Handler
CVSS 7.3
CVE-2025-3993 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-3992 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-3991 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-3990 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-3989 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-3988 HIGH
TOTOLINK N150RT 3.4.0-B20190525 - Buffer Overflow
CVSS 8.8
CVE-2025-2851 HIGH
GL.iNet 4.x - Buffer Overflow in RPC Handler
CVSS 8.0
CVE-2025-46397 HIGH
fig2dev - Buffer Overflow via Bezier Spline Function
CVSS 7.8
CVE-2025-28028 HIGH
TOTOLINK A830R A950RG A3000RU A3100R - Buffer Overflow via downloadFile.cgi v5 Parameter
CVSS 7.3
CVE-2025-28025 HIGH
TOTOLINK A830R A950RG A3000RU A3100R - Buffer Overflow via downloadFile.cgi v14 Parameter
CVSS 7.3
CVE-2025-28022 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Buffer Overflow via v25 Parameter in downloadFile.cgi
CVSS 7.3
CVE-2025-28021 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Buffer Overflow via downloadFile.cgi v14 and v3 Parameters
CVSS 7.3
CVE-2025-28020 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 - Buffer Overflow via v25 Parameter in downloadFile.cgi
CVSS 7.3
CVE-2025-28019 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 - Buffer Overflow in downloadFile.cgi
CVSS 7.3
CVE-2025-28018 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 - Buffer Overflow via downloadFile.cgi v14 Parameter
CVSS 7.3
CVE-2025-28024 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Buffer Overflow in cstecgi.cgi
CVSS 9.8
CVE-2025-3854 HIGH
H3C GR-3000AX < V100R006 - Buffer Overflow
CVSS 8.0
CVE-2025-3845 HIGH
markparticle WebServer <= 1.0 - Buffer Overflow in Buffer::HasWritten
CVSS 7.3
CVE-2025-29625 HIGH
Astrolog v7.70 - Buffer Overflow via FileOpen Environment Variable
CVSS 7.8
CVE-2025-3786 HIGH
Tenda AC15 <15.03.05.19 - Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 4,217
Exploit Likelihood High