Vulnerabilities (CVE)

Filtered by CWE-120
Total 4140 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47341 1 Qualcomm 62 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 59 more 2026-06-17 N/A 7.8 HIGH
memory corruption while processing an image encoding completion event.
CVE-2025-47335 1 Qualcomm 90 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 87 more 2026-06-17 N/A 6.7 MEDIUM
Memory corruption while parsing clock configuration data for a specific hardware type.
CVE-2025-47334 1 Qualcomm 292 Csra6620, Csra6620 Firmware, Csra6640 and 289 more 2026-06-17 N/A 6.7 MEDIUM
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47321 1 Qualcomm 230 Ar8031, Ar8031 Firmware, Ar8035 and 227 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while copying packets received from unix clients.
CVE-2025-46789 1 Zoom 1 Zoom 2026-06-17 N/A 6.5 MEDIUM
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.
CVE-2025-46785 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 6.5 MEDIUM
Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
CVE-2025-46776 1 Fortinet 2 Fortiextender, Fortiextender Firmware 2026-06-17 N/A 6.4 MEDIUM
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
CVE-2025-46714 1 Sandboxie-plus 1 Sandboxie 2026-06-17 N/A 7.8 HIGH
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a extremely large copy into the small allocation. Version 1.15.12 fixes the issue.
CVE-2025-46713 1 Sandboxie-plus 1 Sandboxie 2026-06-17 N/A 7.8 HIGH
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have an arithmetic overflow deep in the memory allocation subsystem that would lead to a smaller allocation than requested, and a buffer overflow. Version 1.15.12 fixes the issue.
CVE-2025-46108 1 Dlink 2 Dir-513, Dir-513 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.
CVE-2025-45866 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 5.4 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
CVE-2025-45865 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.
CVE-2025-45864 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 5.4 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
CVE-2025-45863 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.
CVE-2025-45861 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.
CVE-2025-45859 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 5.4 MEDIUM
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
CVE-2025-45779 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
CVE-2025-44952 1 Open5gs 1 Open5gs 2026-06-17 N/A 7.8 HIGH
A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater than 101.
CVE-2025-44951 1 Open5gs 1 Open5gs 2026-06-17 N/A 7.1 HIGH
A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dev` field with a value with length greater than 32.
CVE-2025-44879 2026-06-17 N/A 7.5 HIGH
WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.