CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,446 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 69 of 89
- CVE-2025-22897LOWCVSS 3.3EG 3.32025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
- CVE-2025-22904CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
- CVE-2025-22907CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
- CVE-2025-22913CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.
- CVE-2025-22916CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
- CVE-2025-22946CRITICALCVSS 9.8EG 9.82025-01-10
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
- CVE-2025-23234LOWCVSS 3.3EG 3.32025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
- CVE-2025-23236HIGHCVSS 8.8EG 8.82025-02-06
Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained.
- CVE-2025-23412HIGHCVSS 7.5EG 7.52025-02-05
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2025-24003HIGHCVSS 8.2EG 8.22025-07-08
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service …
- CVE-2025-24004MEDIUMCVSS 5.2EG 5.22025-07-08
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got r…
- CVE-2025-24131MEDIUMCVSS 6.5EG 6.52025-01-27
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network…
- CVE-2025-24153MEDIUMCVSS 6.7EG 6.72025-01-27
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.
- CVE-2025-24157MEDIUMCVSS 5.6EG 5.62025-03-31
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2025-24209HIGHCVSS 7.0EG 7.02025-03-31
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may l…
- CVE-2025-24237CRITICALCVSS 9.8EG 9.82025-03-31
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to…
- CVE-2025-24266CRITICALCVSS 9.8EG 9.82025-03-31
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
- CVE-2025-24519MEDIUMCVSS 6.5EG 6.52025-11-11
Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack …
- CVE-2025-24956MEDIUMCVSS 6.2EG 6.22025-02-11
A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory co…
- CVE-2025-25052LOWCVSS 3.3EG 3.32025-05-06
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
- CVE-2025-25280MEDIUMCVSS 5.3EG 5.32025-03-03
Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may re…
- CVE-2025-25343CRITICALCVSS 9.8EG 9.82025-02-12
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
- CVE-2025-25453MEDIUMCVSS 4.6EG 4.62025-04-15
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
- CVE-2025-25456CRITICALCVSS 9.8EG 9.82025-04-15
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
- CVE-2025-25458MEDIUMCVSS 4.6EG 4.62025-04-15
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
- CVE-2025-25472MEDIUMCVSS 5.3EG 5.32025-02-18
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
- CVE-2025-25474MEDIUMCVSS 6.5EG 6.52025-02-18
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
- CVE-2025-25505MEDIUMCVSS 6.5EG 6.52025-02-21
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
- CVE-2025-25510MEDIUMCVSS 6.5EG 6.52025-02-21
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.
- CVE-2025-25522HIGHCVSS 7.3EG 7.32025-02-11
Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can directly control the remote target device by successfully exploiting this…
- CVE-2025-25523MEDIUMCVSS 5.9EG 5.92025-02-11
Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target devi…
- CVE-2025-25524MEDIUMCVSS 5.1EG 5.12025-02-11
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can ca…
- CVE-2025-25525MEDIUMCVSS 5.1EG 5.12025-02-11
Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. Attackers who successfully exploit this vulnerability can cause the remot…
- CVE-2025-25526MEDIUMCVSS 5.1EG 5.12025-02-11
Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote targ…
- CVE-2025-25527MEDIUMCVSS 5.1EG 5.12025-02-11
Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cau…
- CVE-2025-25528MEDIUMCVSS 5.1EG 5.12025-02-11
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote d…
- CVE-2025-25529MEDIUMCVSS 5.1EG 5.12025-02-11
Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT rules. Attackers who successfully exploit this vulnerability can cause the re…
- CVE-2025-25530CRITICALCVSS 9.8EG 9.82025-02-11
Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability…
- CVE-2025-25565CRITICALCVSS 9.8EG 9.82025-03-12
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long str…
- CVE-2025-25567CRITICALCVSS 9.8EG 9.82025-03-12
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,
- CVE-2025-25609HIGHCVSS 8.0EG 8.02025-02-28
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
- CVE-2025-25610HIGHCVSS 8.0EG 8.02025-02-28
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
- CVE-2025-25635HIGHCVSS 8.0EG 8.02025-02-28
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
- CVE-2025-25662CRITICALCVSS 9.8EG 9.82025-02-20
Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.
- CVE-2025-25663CRITICALCVSS 9.8EG 9.82025-02-20
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.
- CVE-2025-25664CRITICALCVSS 9.8EG 9.82025-02-20
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.
- CVE-2025-25667CRITICALCVSS 9.8EG 9.82025-02-20
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.
- CVE-2025-25668CRITICALCVSS 9.8EG 9.82025-02-20
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.
- CVE-2025-25674CRITICALCVSS 9.8EG 9.82025-02-20
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.
- CVE-2025-25676CRITICALCVSS 9.8EG 9.82025-02-20
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →