CWE-120— Buffer Copy without Checking Size (Classic Buffer Overflow)
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.— MITRE CWE catalog
4,447 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-120page 77 of 89
- CVE-2025-52870HIGHCVSS 8.1EG 8.12026-02-11
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in …
- CVE-2025-52872HIGHCVSS 8.1EG 8.12026-01-02
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fi…
- CVE-2025-52908CRITICALCVSS 9.8EG 9.82026-04-07
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflo…
- CVE-2025-52909CRITICALCVSS 9.8EG 9.82026-04-07
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflo…
- CVE-2025-5295CRITICALCVSS 9.8EG 9.82025-05-28
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code of the component PORT Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely.…
- CVE-2025-52960MEDIUMCVSS 5.9EG 5.92025-10-09
A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of S…
- CVE-2025-5330CRITICALCVSS 9.8EG 9.82025-05-29
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component RETR Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack …
- CVE-2025-5331CRITICALCVSS 9.8EG 9.82025-05-29
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remo…
- CVE-2025-53474HIGHCVSS 7.5EG 7.52025-10-15
When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) …
- CVE-2025-5356CRITICALCVSS 9.8EG 9.82025-05-30
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack…
- CVE-2025-5357CRITICALCVSS 9.8EG 9.82025-05-30
A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PWD Command Handler. The manipulation leads to buffer overflow. The attack…
- CVE-2025-53711HIGHCVSS 7.5EG 7.52025-07-29
A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to c…
- CVE-2025-53712HIGHCVSS 7.5EG 7.52025-07-29
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web serv…
- CVE-2025-53713HIGHCVSS 7.5EG 7.52025-07-29
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web serv…
- CVE-2025-53888CRITICALCVSS 9.8EG 9.82025-07-18
RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions up to and including 2025.04. Assertions are usually compiled out in pr…
- CVE-2025-53966HIGHCVSS 8.4EG 8.42026-01-05
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow during handling of an IOCTL message.
- CVE-2025-5408CRITICALCVSS 9.8EG 9.82025-06-01
A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.c…
- CVE-2025-54632MEDIUMCVSS 6.8EG 6.82025-08-06
Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.
- CVE-2025-54641MEDIUMCVSS 6.7EG 6.72025-08-06
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-54642MEDIUMCVSS 6.7EG 6.72025-08-06
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-55131HIGHCVSS 7.1EG 7.12026-01-20
A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and o…
- CVE-2025-55297HIGHCVSS 8.8EG 8.82025-08-21
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability …
- CVE-2025-5547CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component CDUP Command Handler. The manipulation leads to buffer overflow. The attack may be i…
- CVE-2025-5548CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack…
- CVE-2025-5549CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component PASV Command Handler. The manipulation leads to buffer overflow. The attack …
- CVE-2025-55495MEDIUMCVSS 6.5EG 6.52025-08-27
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- CVE-2025-55499MEDIUMCVSS 6.5EG 6.52025-08-20
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.
- CVE-2025-5550CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component PBSZ Command Handler. The manipulation leads to buffer overflow. The attack may be laun…
- CVE-2025-5551CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. This affects an unknown part of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the atta…
- CVE-2025-55599HIGHCVSS 7.5EG 7.52025-08-22
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
- CVE-2025-55602HIGHCVSS 7.5EG 7.52025-08-22
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
- CVE-2025-55603HIGHCVSS 7.5EG 7.52025-08-22
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
- CVE-2025-55605HIGHCVSS 7.5EG 7.52025-08-22
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter.
- CVE-2025-55606HIGHCVSS 7.5EG 7.52025-08-22
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter.
- CVE-2025-55611HIGHCVSS 7.5EG 7.52025-08-22
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
- CVE-2025-55613CRITICALCVSS 9.8EG 9.82025-08-22
Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.
- CVE-2025-55847HIGHCVSS 8.8EG 8.82025-09-26
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit th…
- CVE-2025-5592CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component PASSIVE Command Handler. The manipulation leads to buffer overflow. The at…
- CVE-2025-5593CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack …
- CVE-2025-5594CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component SET Command Handler. The manipulation leads to buffer overflow. The attack can be initiated rem…
- CVE-2025-5595CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component PROGRESS Command Handler. The manipulation leads to buffer overflow. The attack may be initiated …
- CVE-2025-5596CRITICALCVSS 9.8EG 9.82025-06-04
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component REGET Command Handler. The manipulation leads to buffer overflow. It is possible to launch the atta…
- CVE-2025-5601HIGHCVSS 6.5EG 7.82025-06-04
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
- CVE-2025-5607HIGHCVSS 8.8EG 8.82025-06-04
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. Th…
- CVE-2025-5608HIGHCVSS 8.8EG 8.82025-06-04
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to buffer overflow. It …
- CVE-2025-5609HIGHCVSS 8.8EG 8.82025-06-04
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. …
- CVE-2025-5629CRITICALCVSS 9.8EG 9.82025-06-05
A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of the component HTTP Handler. The manipulation of the argument …
- CVE-2025-5634CRITICALCVSS 9.8EG 9.82025-06-05
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely.…
- CVE-2025-5635CRITICALCVSS 9.8EG 9.82025-06-05
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The …
- CVE-2025-5636CRITICALCVSS 9.8EG 9.82025-06-05
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SET Command Handler. The manipulation leads to buffer overflow. The attack may be init…
Map vulnerabilities like CWE-120 to your infrastructure
EchelonGraph correlates every CVE — across CWE-120 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →