CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,114
Total CVEs
330
Critical
614
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 80
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 28
9 Fedoraproject 23
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,114)

CVE-2024-25139
10.0

This vulnerability allows remote attackers to execute arbitrary code with root privileges on TP-Link Omada ER605 routers. An integer overflow in the c...

Mar 14, 2024
CVE-2024-22039
10.0

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on affected Siemens fire safety systems due ...

Mar 12, 2024
CVE-2023-1424
10.0

A critical buffer overflow vulnerability in Mitsubishi Electric MELSEC iQ-F and iQ-R Series CPU modules allows remote unauthenticated attackers to exe...

May 24, 2023
CVE-2021-33972
10.0

CVE-2021-33972 is a buffer overflow vulnerability in Qihoo 360 Safe Browser that allows attackers to execute arbitrary code with elevated privileges. ...

Apr 19, 2023
CVE-2021-33975
10.0

A buffer overflow vulnerability in Qihoo 360 Total Security allows attackers to execute arbitrary code with elevated privileges. This affects users ru...

Apr 19, 2023
CVE-2023-24482
10.0

This CVE describes a critical buffer overflow vulnerability in COMOS software's cache validation service. Attackers can exploit this Structured Except...

Feb 14, 2023
CVE-2022-22683
10.0

This is a critical buffer overflow vulnerability in Synology Media Server's CGI component that allows remote attackers to execute arbitrary code. Atta...

Jul 28, 2022
CVE-2022-31481
10.0

An unauthenticated buffer overflow vulnerability in HID Mercury Intelligent Controllers allows attackers to execute arbitrary code by sending speciall...

Jun 6, 2022
CVE-2022-22570
10.0

A buffer overflow vulnerability in UniFi Door Access Reader Lite firmware allows attackers with network access to execute arbitrary code and take cont...

Apr 1, 2022
CVE-2025-20333
KEV EPSS 18.7% 9.9

This critical vulnerability in Cisco ASA and FTD VPN web servers allows authenticated remote attackers to execute arbitrary code as root. Attackers wi...

Sep 25, 2025
CVE-2023-36355
9.9

This vulnerability in TP-Link TL-WR940N V4 routers allows attackers to trigger a buffer overflow via the ipStart parameter in the web interface. Attac...

Jun 22, 2023
CVE-2025-70314
9.8

CVE-2025-70314 is a critical buffer overflow vulnerability in webfsd 1.21 that allows remote attackers to execute arbitrary code by sending a speciall...

Feb 12, 2026
CVE-2026-25994
9.8

A buffer overflow vulnerability in PJSIP's PJNATH ICE Session component allows attackers to execute arbitrary code or cause denial of service by sendi...

Feb 11, 2026
CVE-2020-37068
9.8

CVE-2020-37068 is a critical buffer overflow vulnerability in Konica Minolta FTP Utility 1.0 that allows attackers to crash the FTP server and potenti...

Feb 3, 2026
CVE-2025-67186
9.8

This critical buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to execute arbitrary code or cause denial of service by...

Feb 3, 2026
CVE-2025-67188
9.8

This buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...

Feb 3, 2026
CVE-2026-24793
9.8

This CVE describes a classic buffer overflow vulnerability in AzerothCore's Wrath of the Lich King implementation, specifically in the zlib dependency...

Jan 27, 2026
CVE-2021-47854
9.8

CVE-2021-47854 is a critical buffer overflow vulnerability in DD-WRT's UPnP service that allows remote attackers to execute arbitrary code on affected...

Jan 21, 2026
CVE-2022-50922
9.8

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing a specially crafte...

Jan 13, 2026
CVE-2025-69258
9.8

An unauthenticated remote attacker can exploit a LoadLibraryEX vulnerability in Trend Micro Apex Central to load malicious DLLs, leading to arbitrary ...

Jan 8, 2026
CVE-2025-66647
9.8

A buffer overflow vulnerability in RIOT OS's IPv6 fragmentation reassembly allows attackers to corrupt memory by sending specially crafted IPv6 packet...

Dec 17, 2025
CVE-2025-67073
9.8

A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by ...

Dec 17, 2025
CVE-2025-65834
9.8

CVE-2025-65834 is a critical buffer overflow vulnerability in Shotcut video editor that allows remote code execution when processing malicious MLT pro...

Dec 16, 2025
CVE-2023-53874
9.8

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field. Attackers can crash the application by overw...

Dec 15, 2025
CVE-2025-11780
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices. An attacker can exploit this by sen...

Dec 2, 2025
CVE-2025-50402
9.8

The FAST FAC1200R F400_FAC1200R_Q device contains a buffer overflow vulnerability in the password handling function that allows attackers to execute a...

Nov 26, 2025
CVE-2025-50399
9.8

This vulnerability allows remote attackers to execute arbitrary code on FAST FAC1200R F400_FAC1200R_Q devices by exploiting a buffer overflow in the p...

Nov 26, 2025
CVE-2025-60553
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers via a buffer overflow in the web interface's WAN config...

Oct 24, 2025
CVE-2025-60548
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR600L routers by exploiting a buffer overflow in the formLanSetupRout...

Oct 24, 2025
CVE-2025-55613
9.8

A buffer overflow vulnerability in Tenda O3V2 routers allows attackers to execute arbitrary code by sending specially crafted requests to the fromSafe...

Aug 22, 2025
CVE-2025-29365
9.8

CVE-2025-29365 is a buffer overflow vulnerability in spimsimulator's READ_STRING_SYSCALL function that allows attackers to execute arbitrary code or c...

Aug 22, 2025
CVE-2025-8854
9.8

A stack-based buffer overflow vulnerability in bulletphysics bullet3's LoadOFF function allows remote attackers to execute arbitrary code by providing...

Aug 11, 2025
CVE-2025-53888
9.8

RIOT-OS versions up to 2025.04 have a buffer overflow vulnerability in the l2filter_add() function where assertions are used for input validation inst...

Jul 18, 2025
CVE-2025-51630
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK N350RT routers by exploiting a buffer overflow in the ePort parameter...

Jul 17, 2025
CVE-2025-7673
9.8

A buffer overflow vulnerability in the zhttpd URL parser of Zyxel VMG8825-T50K routers allows unauthenticated attackers to cause denial-of-service or ...

Jul 16, 2025
CVE-2023-38036
9.8

This is a critical buffer overflow vulnerability in Ivanti Avalanche Manager that allows unauthenticated attackers to potentially execute arbitrary co...

Jul 12, 2025
CVE-2025-32105
9.8

A buffer overflow vulnerability in Sangoma IMG2020 HTTP server allows unauthenticated attackers to execute arbitrary code remotely. This affects all s...

Jun 3, 2025
CVE-2025-45863
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via a buffer overflow in the formMapDelDevice interfac...

May 13, 2025
CVE-2025-45861
9.8

This CVE describes a critical buffer overflow vulnerability in TOTOLINK A3002R routers that allows remote attackers to execute arbitrary code or cause...

May 13, 2025
CVE-2025-45779
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the formSetPPTPUserList handler. A...

May 12, 2025
CVE-2025-29046
9.8

A buffer overflow vulnerability in ALFA WiFi CampPro router firmware allows remote attackers to execute arbitrary code by sending specially crafted GA...

Apr 17, 2025
CVE-2025-29044
9.8

A buffer overflow vulnerability in Netgear R61 router firmware allows remote attackers to execute arbitrary code by sending specially crafted QUERY_ST...

Apr 17, 2025
CVE-2025-25456
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Atta...

Apr 15, 2025
CVE-2025-24237
9.8

A buffer overflow vulnerability in Apple operating systems allows malicious apps to cause system crashes or potentially execute arbitrary code. This a...

Mar 31, 2025
CVE-2025-26006
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Telesquare TLR-2005KSH routers by exploiting a buffer overflow...

Mar 26, 2025
CVE-2025-26008
9.8

An unauthenticated stack overflow vulnerability in Telesquare TLR-2005KSH routers allows remote attackers to execute arbitrary code by sending special...

Mar 26, 2025
CVE-2025-26002
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Telesquare TLR-2005KSH routers by exploiting a buffer overflow...

Mar 26, 2025
CVE-2025-26004
9.8

The Telesquare TLR-2005KSH router firmware version 1.1.4 contains a stack buffer overflow vulnerability in the admin.cgi endpoint when processing the ...

Mar 26, 2025
CVE-2025-27836
9.8

A buffer overflow vulnerability in the BJ10V device driver in Ghostscript allows attackers to execute arbitrary code or cause denial of service. This ...

Mar 25, 2025
CVE-2025-27831
9.8

A buffer overflow vulnerability in Artifex Ghostscript's DOCXWRITE/TXTWRITE device allows attackers to execute arbitrary code or cause denial of servi...

Mar 25, 2025

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,114 CVEs classified as CWE-120, with 330 rated critical and 614 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free