CWE-120
High likelihoodBuffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Parent: CWE-787 - Out-of-bounds Write
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
4,085 vulnerabilities with CWE-120
CVE-2026-34124
MEDIUM
Denial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34875
CRITICAL
Mbed TLS through 3.6.5 - Buffer Overflow
CVSS 9.8
CVE-2026-31027
CRITICAL
TOTOlink A3600R v5.9c.4959 - Buffer Overflow
CVSS 9.8
CVE-2026-5279
HIGH
Google Chrome <146.0.7680.178 - Memory Corruption
CVSS 8.8
CVE-2026-5164
MEDIUM
Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request
CVSS 6.7
CVE-2026-1679
HIGH
net: eswifi socket send payload length not bounded
CVSS 7.3
CVE-2026-4976
HIGH
Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
CVSS 8.8
CVE-2026-29976
MEDIUM
ZerBea hcxpcapngtool 7.0.1-43-g2ee308e - Buffer Overflow
CVSS 6.2
CVE-2026-4862
HIGH
UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow
CVSS 8.8
CVE-2026-28875
HIGH
Apple Ios And Ipados < 26.4 - Buffer Overflow
CVSS 7.5
CVE-2026-28858
CRITICAL
Apple Ios And Ipados < 26.4 - Buffer Overflow
CVSS 9.8
CVE-2026-28841
MEDIUM
Apple Macos < 26.4 - Buffer Overflow
CVSS 6.2
CVE-2026-4729
CRITICAL
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4721
CRITICAL
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4720
CRITICAL
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4690
HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687
HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-30006
MEDIUM
XnSoft NConvert 7.230 - Buffer Overflow
CVSS 6.2
CVE-2026-4565
HIGH
Tenda AC21 SetNetControlList formSetQosBand buffer overflow
CVSS 8.8
CVE-2026-4488
HIGH
UTT HiPER 1250GW setSysAdm strcpy buffer overflow
CVSS 8.8
CVE-2026-4487
HIGH
UTT HiPER 1200GW websHostFilter strcpy buffer overflow
CVSS 8.8
CVE-2026-27459
CRITICAL
pyOpenSSL DTLS cookie callback buffer overflow
CVSS 9.8
CVE-2026-4318
HIGH
UTT HiPER 810G formApLbConfig strcpy buffer overflow
CVSS 8.8
CVE-2026-4227
HIGH
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
CVSS 8.8
Details
Vulnerabilities
4,085
Exploit Likelihood
High