CWE-120

High likelihood

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Parent: CWE-787 - Out-of-bounds Write

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

4,198 vulnerabilities with CWE-120
CVE-2026-5979 HIGH
D-Link DIR-605L POST Request formVirtualServ buffer overflow
CVSS 8.8
CVE-2026-30075 HIGH
OpenAirInterface 2.2.0 - Buffer Overflow
CVSS 7.5
CVE-2026-5734 CRITICAL
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
CVSS 9.8
CVE-2026-21382 HIGH
Buffer Copy Without Checking Size of Input in Power Management IC
CVSS 7.8
CVE-2026-31066 MEDIUM
UTT Aggressive HiPER 810G v3v1.7.7-171114 - Buffer Overflow
CVSS 4.5
CVE-2026-31065 MEDIUM
UTT Aggressive 520W v3v1.7.7-180627 - Buffer Overflow
CVSS 4.5
CVE-2026-31063 MEDIUM
UTT Aggressive HiPER 1200GW 2.5.3-170306 - Buffer Overflow
CVSS 4.5
CVE-2026-31062 MEDIUM
UTT Aggressive 520W v3v1.7.7-180627 - Buffer Overflow
CVSS 4.5
CVE-2026-31061 MEDIUM
UTT Aggressive HiPER 810G v3v1.7.7-171114 - Buffer Overflow
CVSS 4.5
CVE-2026-31060 MEDIUM
UTT Aggressive HiPER 810G v3v1.7.7-171114 - Buffer Overflow
CVSS 4.5
CVE-2026-31058 MEDIUM
UTT Aggressive HiPER 1200GW v2.5.3-170306 - Buffer Overflow
CVSS 4.5
CVE-2026-5567 HIGH
Tenda M3 Destination setAdvPolicyData buffer overflow
CVSS 8.8
CVE-2026-5566 HIGH
UTT HiPER 1250GW formNatStaticMap strcpy buffer overflow
CVSS 8.8
CVE-2026-34124 MEDIUM
Denial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34875 CRITICAL
Mbed TLS through 3.6.5 - Buffer Overflow
CVSS 9.8
CVE-2026-31027 CRITICAL
TOTOlink A3600R v5.9c.4959 - Buffer Overflow
CVSS 9.8
CVE-2026-5279 HIGH
Google Chrome <146.0.7680.178 - Memory Corruption
CVSS 8.8
CVE-2026-5164 MEDIUM
Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request
CVSS 6.7
CVE-2026-1679 HIGH
net: eswifi socket send payload length not bounded
CVSS 7.3
CVE-2026-4976 HIGH
Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
CVSS 8.8
CVE-2026-29976 MEDIUM
ZerBea hcxpcapngtool 7.0.1-43-g2ee308e - Buffer Overflow
CVSS 6.2
CVE-2026-4862 HIGH
UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow
CVSS 8.8
CVE-2026-28875 HIGH
iOS and iPadOS < 26.4 - Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2026-28858 CRITICAL
iOS and iPadOS < 26.4 - Remote Denial of Service and Memory Corruption via Buffer Overflow
CVSS 9.8
CVE-2026-28841 MEDIUM
macOS < 26.4 - Buffer Overflow via Improved Size Validation
CVSS 6.2
Details
Vulnerabilities 4,198
Exploit Likelihood High