CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,085 vulnerabilities with CWE-120
CVE-2026-34124 MEDIUM
Denial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34875 CRITICAL
Mbed TLS through 3.6.5 - Buffer Overflow
CVSS 9.8
CVE-2026-31027 CRITICAL
TOTOlink A3600R v5.9c.4959 - Buffer Overflow
CVSS 9.8
CVE-2026-5279 HIGH
Google Chrome <146.0.7680.178 - Memory Corruption
CVSS 8.8
CVE-2026-5164 MEDIUM
Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request
CVSS 6.7
CVE-2026-1679 HIGH
net: eswifi socket send payload length not bounded
CVSS 7.3
CVE-2026-4976 HIGH
Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
CVSS 8.8
CVE-2026-29976 MEDIUM
ZerBea hcxpcapngtool 7.0.1-43-g2ee308e - Buffer Overflow
CVSS 6.2
CVE-2026-4862 HIGH
UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow
CVSS 8.8
CVE-2026-28875 HIGH
Apple Ios And Ipados < 26.4 - Buffer Overflow
CVSS 7.5
CVE-2026-28858 CRITICAL
Apple Ios And Ipados < 26.4 - Buffer Overflow
CVSS 9.8
CVE-2026-28841 MEDIUM
Apple Macos < 26.4 - Buffer Overflow
CVSS 6.2
CVE-2026-4729 CRITICAL
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4721 CRITICAL
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4720 CRITICAL
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVSS 9.8
CVE-2026-4690 HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689 CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687 HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-30006 MEDIUM
XnSoft NConvert 7.230 - Buffer Overflow
CVSS 6.2
CVE-2026-4565 HIGH
Tenda AC21 SetNetControlList formSetQosBand buffer overflow
CVSS 8.8
CVE-2026-4488 HIGH
UTT HiPER 1250GW setSysAdm strcpy buffer overflow
CVSS 8.8
CVE-2026-4487 HIGH
UTT HiPER 1200GW websHostFilter strcpy buffer overflow
CVSS 8.8
CVE-2026-27459 CRITICAL
pyOpenSSL DTLS cookie callback buffer overflow
CVSS 9.8
CVE-2026-4318 HIGH
UTT HiPER 810G formApLbConfig strcpy buffer overflow
CVSS 8.8
CVE-2026-4227 HIGH
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
CVSS 8.8
Details
Vulnerabilities 4,085
Exploit Likelihood High