CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,114)
This vulnerability allows remote attackers to execute arbitrary code with root privileges on TP-Link Omada ER605 routers. An integer overflow in the c...
Mar 14, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on affected Siemens fire safety systems due ...
Mar 12, 2024A critical buffer overflow vulnerability in Mitsubishi Electric MELSEC iQ-F and iQ-R Series CPU modules allows remote unauthenticated attackers to exe...
May 24, 2023CVE-2021-33972 is a buffer overflow vulnerability in Qihoo 360 Safe Browser that allows attackers to execute arbitrary code with elevated privileges. ...
Apr 19, 2023A buffer overflow vulnerability in Qihoo 360 Total Security allows attackers to execute arbitrary code with elevated privileges. This affects users ru...
Apr 19, 2023This CVE describes a critical buffer overflow vulnerability in COMOS software's cache validation service. Attackers can exploit this Structured Except...
Feb 14, 2023This is a critical buffer overflow vulnerability in Synology Media Server's CGI component that allows remote attackers to execute arbitrary code. Atta...
Jul 28, 2022An unauthenticated buffer overflow vulnerability in HID Mercury Intelligent Controllers allows attackers to execute arbitrary code by sending speciall...
Jun 6, 2022A buffer overflow vulnerability in UniFi Door Access Reader Lite firmware allows attackers with network access to execute arbitrary code and take cont...
Apr 1, 2022This critical vulnerability in Cisco ASA and FTD VPN web servers allows authenticated remote attackers to execute arbitrary code as root. Attackers wi...
Sep 25, 2025This vulnerability in TP-Link TL-WR940N V4 routers allows attackers to trigger a buffer overflow via the ipStart parameter in the web interface. Attac...
Jun 22, 2023CVE-2025-70314 is a critical buffer overflow vulnerability in webfsd 1.21 that allows remote attackers to execute arbitrary code by sending a speciall...
Feb 12, 2026A buffer overflow vulnerability in PJSIP's PJNATH ICE Session component allows attackers to execute arbitrary code or cause denial of service by sendi...
Feb 11, 2026CVE-2020-37068 is a critical buffer overflow vulnerability in Konica Minolta FTP Utility 1.0 that allows attackers to crash the FTP server and potenti...
Feb 3, 2026This critical buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to execute arbitrary code or cause denial of service by...
Feb 3, 2026This buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...
Feb 3, 2026This CVE describes a classic buffer overflow vulnerability in AzerothCore's Wrath of the Lich King implementation, specifically in the zlib dependency...
Jan 27, 2026CVE-2021-47854 is a critical buffer overflow vulnerability in DD-WRT's UPnP service that allows remote attackers to execute arbitrary code on affected...
Jan 21, 2026Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing a specially crafte...
Jan 13, 2026An unauthenticated remote attacker can exploit a LoadLibraryEX vulnerability in Trend Micro Apex Central to load malicious DLLs, leading to arbitrary ...
Jan 8, 2026A buffer overflow vulnerability in RIOT OS's IPv6 fragmentation reassembly allows attackers to corrupt memory by sending specially crafted IPv6 packet...
Dec 17, 2025A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by ...
Dec 17, 2025CVE-2025-65834 is a critical buffer overflow vulnerability in Shotcut video editor that allows remote code execution when processing malicious MLT pro...
Dec 16, 2025GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field. Attackers can crash the application by overw...
Dec 15, 2025This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can exploit this by sen...
Dec 2, 2025The FAST FAC1200R F400_FAC1200R_Q device contains a buffer overflow vulnerability in the password handling function that allows attackers to execute a...
Nov 26, 2025This vulnerability allows remote attackers to execute arbitrary code on FAST FAC1200R F400_FAC1200R_Q devices by exploiting a buffer overflow in the p...
Nov 26, 2025This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers via a buffer overflow in the web interface's WAN config...
Oct 24, 2025This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers by exploiting a buffer overflow in the formLanSetupRout...
Oct 24, 2025A buffer overflow vulnerability in Tenda O3V2 routers allows attackers to execute arbitrary code by sending specially crafted requests to the fromSafe...
Aug 22, 2025CVE-2025-29365 is a buffer overflow vulnerability in spimsimulator's READ_STRING_SYSCALL function that allows attackers to execute arbitrary code or c...
Aug 22, 2025A stack-based buffer overflow vulnerability in bulletphysics bullet3's LoadOFF function allows remote attackers to execute arbitrary code by providing...
Aug 11, 2025RIOT-OS versions up to 2025.04 have a buffer overflow vulnerability in the l2filter_add() function where assertions are used for input validation inst...
Jul 18, 2025This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK N350RT routers by exploiting a buffer overflow in the ePort parameter...
Jul 17, 2025A buffer overflow vulnerability in the zhttpd URL parser of Zyxel VMG8825-T50K routers allows unauthenticated attackers to cause denial-of-service or ...
Jul 16, 2025This is a critical buffer overflow vulnerability in Ivanti Avalanche Manager that allows unauthenticated attackers to potentially execute arbitrary co...
Jul 12, 2025A buffer overflow vulnerability in Sangoma IMG2020 HTTP server allows unauthenticated attackers to execute arbitrary code remotely. This affects all s...
Jun 3, 2025This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via a buffer overflow in the formMapDelDevice interfac...
May 13, 2025This CVE describes a critical buffer overflow vulnerability in TOTOLINK A3002R routers that allows remote attackers to execute arbitrary code or cause...
May 13, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the formSetPPTPUserList handler. A...
May 12, 2025A buffer overflow vulnerability in ALFA WiFi CampPro router firmware allows remote attackers to execute arbitrary code by sending specially crafted GA...
Apr 17, 2025A buffer overflow vulnerability in Netgear R61 router firmware allows remote attackers to execute arbitrary code by sending specially crafted QUERY_ST...
Apr 17, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Atta...
Apr 15, 2025A buffer overflow vulnerability in Apple operating systems allows malicious apps to cause system crashes or potentially execute arbitrary code. This a...
Mar 31, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Telesquare TLR-2005KSH routers by exploiting a buffer overflow...
Mar 26, 2025An unauthenticated stack overflow vulnerability in Telesquare TLR-2005KSH routers allows remote attackers to execute arbitrary code by sending special...
Mar 26, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Telesquare TLR-2005KSH routers by exploiting a buffer overflow...
Mar 26, 2025The Telesquare TLR-2005KSH router firmware version 1.1.4 contains a stack buffer overflow vulnerability in the admin.cgi endpoint when processing the ...
Mar 26, 2025A buffer overflow vulnerability in the BJ10V device driver in Ghostscript allows attackers to execute arbitrary code or cause denial of service. This ...
Mar 25, 2025A buffer overflow vulnerability in Artifex Ghostscript's DOCXWRITE/TXTWRITE device allows attackers to execute arbitrary code or cause denial of servi...
Mar 25, 2025About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,114 CVEs classified as CWE-120, with 330 rated critical and 614 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free