CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,446 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 68 of 89
- CVE-2025-14534CRITICALCVSS 9.8EG 9.82025-12-11
A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manipulation of the argument NatBind can lead to buffer over…
- CVE-2025-14535CRITICALCVSS 9.8EG 9.82025-12-11
A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiat…
- CVE-2025-14656HIGHCVSS 8.8EG 8.82025-12-14
A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedWifi. Executing a manipulation of the argument schedStartTime/schedEndTime can lead to buffer overflow. The attack may b…
- CVE-2025-14708CRITICALCVSS 9.8EG 9.82025-12-15
A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argume…
- CVE-2025-14709CRITICALCVSS 9.8EG 9.82025-12-15
A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the arg…
- CVE-2025-14911MEDIUMCVSS 6.5EG 6.52026-01-27
User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overflow the bounding container.
- CVE-2025-15089HIGHCVSS 8.8EG 8.82025-12-25
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried …
- CVE-2025-15090HIGHCVSS 8.8EG 8.82025-12-25
A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack m…
- CVE-2025-15091HIGHCVSS 8.8EG 8.82025-12-26
A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to i…
- CVE-2025-15092HIGHCVSS 8.8EG 8.82025-12-26
A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument remark leads to buffer overflow. It is possible to launch the atta…
- CVE-2025-15189HIGHCVSS 8.8EG 8.82025-12-29
A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated …
- CVE-2025-15193HIGHCVSS 8.8EG 8.82025-12-29
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible…
- CVE-2025-15215HIGHCVSS 8.8EG 8.82025-12-30
A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. This manipulation of the argument list cau…
- CVE-2025-15217HIGHCVSS 8.8EG 8.82025-12-30
A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack c…
- CVE-2025-15218HIGHCVSS 8.8EG 8.82025-12-30
A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing a manipulation…
- CVE-2025-15356HIGHCVSS 8.8EG 8.82025-12-30
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer o…
- CVE-2025-15428HIGHCVSS 8.8EG 8.82026-01-02
A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemoteControl. This manipulation of the argument Profile causes buffer overflow. It is possible to initiate the attack …
- CVE-2025-15429HIGHCVSS 8.8EG 8.82026-01-02
A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formConfigCliForEngineerOnly. Such manipulation of the argument addCommand leads to buffe…
- CVE-2025-15430HIGHCVSS 8.8EG 8.82026-01-02
A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formFtpServerShareDirSelcet. Performing a manipulation of the argument oldfilename results in buffer overflow. …
- CVE-2025-15431HIGHCVSS 8.8EG 8.82026-01-02
A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDirConfig. Executing a manipulation of the argument filename can lead to buffer overflow. The attack can be launched r…
- CVE-2025-15459HIGHCVSS 8.8EG 8.82026-01-05
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formUser. Such manipulation of the argument passwd1 leads to buffer overflow. The attack may be l…
- CVE-2025-15460HIGHCVSS 8.8EG 8.82026-01-05
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitati…
- CVE-2025-15461HIGHCVSS 8.8EG 8.82026-01-05
A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be exe…
- CVE-2025-15462HIGHCVSS 8.8EG 8.82026-01-05
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart leads to buffer overflow. The attack is possible to be car…
- CVE-2025-15467CRITICALCVSS 8.8EG 9.82026-01-27
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or…
- CVE-2025-1587MEDIUMCVSS 5.3EG 5.32025-02-23
A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argu…
- CVE-2025-1660HIGHCVSS 7.8EG 7.82025-04-01
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- CVE-2025-1786MEDIUMCVSS 5.3EG 5.32025-03-01
A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer over…
- CVE-2025-1852HIGHCVSS 8.8EG 8.82025-03-03
A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to bu…
- CVE-2025-1864CRITICALCVSS 9.8EG 9.82025-03-03
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.
- CVE-2025-1895MEDIUMCVSS 6.5EG 6.52025-03-04
A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to…
- CVE-2025-1896MEDIUMCVSS 6.5EG 6.52025-03-04
A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to buffer overflow. The attack can …
- CVE-2025-1897MEDIUMCVSS 6.5EG 6.52025-03-04
A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The manipulation of the argument list leads to buffer overf…
- CVE-2025-1898MEDIUMCVSS 6.5EG 6.52025-03-04
A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to buffer ov…
- CVE-2025-1899MEDIUMCVSS 6.5EG 6.52025-03-04
A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer…
- CVE-2025-20115HIGHCVSS 8.6EG 8.62025-03-12
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due …
- CVE-2025-20128MEDIUMCVSS 5.3EG 5.32025-01-22
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a…
- CVE-2025-20149MEDIUMCVSS 6.5EG 6.52025-09-24
A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerabi…
- CVE-2025-2017HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required …
- CVE-2025-20222HIGHCVSS 8.6EG 8.62025-08-14
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attack…
- CVE-2025-20333CRITICALCVSS 9.9EG 9.9⚠ KEV2025-09-25
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an…
- CVE-2025-20709HIGHCVSS 8.8EG 8.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2025-20748MEDIUMCVSS 6.7EG 6.72025-11-04
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed fo…
- CVE-2025-21426MEDIUMCVSS 6.6EG 6.62025-07-08
Memory corruption while processing camera TPG write request.
- CVE-2025-21443HIGHCVSS 7.8EG 7.82025-04-07
Memory corruption while processing message content in eAVB.
- CVE-2025-21444HIGHCVSS 7.8EG 7.82025-07-08
Memory corruption while copying the result to the transmission queue in EMAC.
- CVE-2025-21445HIGHCVSS 7.8EG 7.82025-07-08
Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host.
- CVE-2025-21476HIGHCVSS 7.8EG 7.82025-09-24
Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
- CVE-2025-21481HIGHCVSS 7.8EG 7.82025-09-24
Memory corruption while performing private key encryption in trusted application.
- CVE-2025-21780HIGHCVSS 7.8EG 7.82025-02-27
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table() It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffe…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →