CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,147)
This vulnerability allows arbitrary code execution by processing a maliciously crafted audio file. It affects Apple devices running macOS, tvOS, watch...
Sep 8, 2021CVE-2021-28580 is a buffer overflow vulnerability in Adobe Medium versions 2.4.5.331 and earlier that allows remote code execution when a user opens a...
Sep 8, 2021This vulnerability allows remote attackers to execute arbitrary code on DEF CON 27 badges by sending specially crafted oversized packets via the NFMI ...
Aug 4, 2021CVE-2015-2098 is a critical stack-based buffer overflow vulnerability in WebGate eDVR Manager that allows remote attackers to execute arbitrary code o...
Jul 22, 2021This is a buffer overflow vulnerability in D-Link DAP-1330 routers that allows network-adjacent attackers to execute arbitrary code without authentica...
Jul 15, 2021This buffer overflow vulnerability in FortiMail allows authenticated webmail users to execute arbitrary code via crafted HTTP requests. It affects For...
Jul 9, 2021A buffer overflow vulnerability in the BMC firmware for Intel Server Board M10JNP2SB allows unauthenticated attackers with adjacent network access to ...
Jun 9, 2021A buffer overflow vulnerability in Pulse Connect Secure's Windows File Resource Profiles allows authenticated users with SMB share browsing privileges...
May 27, 2021This buffer overflow vulnerability in FFmpeg's MOV file handling allows attackers to execute arbitrary code, cause denial of service, or leak sensitiv...
May 26, 2021This CVE describes a buffer overflow vulnerability in FFmpeg's DNN module that allows remote attackers to execute arbitrary code by exploiting imprope...
May 26, 2021This vulnerability allows an authenticated attacker to exploit a buffer overflow in the Skyworth RN510 router's web interface. By sending a specially ...
Apr 9, 2021CVE-2021-30123 is a buffer overflow vulnerability in FFmpeg's libavcodec library that allows remote attackers to execute arbitrary code by providing a...
Apr 7, 2021A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service. This affe...
Mar 29, 2021CVE-2020-36152 is a buffer overflow vulnerability in the readDataVar function of libmysofa's hdf/dataobject.c. Attackers can exploit this by providing...
Feb 8, 2021This vulnerability allows unauthenticated remote attackers to cause a denial of service by sending specially crafted IPv6 packets over IPsec VPN conne...
Aug 14, 2025A memory corruption vulnerability in Cisco IOS XR's BGP confederation implementation allows unauthenticated remote attackers to cause denial of servic...
Mar 12, 2025This CVE describes a classic buffer overflow vulnerability in RTI Connext Professional's Core Libraries and Routing Service. Attackers can exploit thi...
Dec 13, 2024Multiple vulnerabilities in Cisco Small Business Series Switches web interface allow unauthenticated remote attackers to cause denial of service or ex...
May 18, 2023This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to execute arbitrary code with root privileges or c...
May 18, 2023This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to cause denial of service or execute arbitrary cod...
May 18, 2023Multiple vulnerabilities in Cisco Small Business Series Switches web interface allow unauthenticated remote attackers to cause denial of service or ex...
May 18, 2023This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to execute arbitrary code with root privileges or c...
May 18, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges or cause denial of service on affected Cisco...
May 18, 2023CVE-2021-21282 is a buffer overflow vulnerability in Contiki-NG's RPL implementations when operating in source-routing mode. Attackers can exploit thi...
Jun 18, 2021CVE-2022-24754 is a stack-buffer overflow vulnerability in PJSIP multimedia communication library that affects users accepting hashed digest credentia...
Mar 11, 2022This vulnerability allows authenticated remote attackers to trigger a buffer overflow in Cisco ASA and FTD software web services interface by sending ...
Apr 29, 2021A buffer overflow vulnerability in the WiFi driver of Samsung Exynos 1380, 1480, 2400, and 1580 mobile processors allows attackers to execute arbitrar...
Jan 5, 2026A buffer overflow vulnerability in Samsung Exynos mobile processors allows attackers to execute arbitrary code or cause denial of service by sending s...
Jan 5, 2026A buffer overflow vulnerability in GPAC version 2.5 allows local attackers to execute arbitrary code on affected systems. This affects systems running...
Feb 28, 2025This CVE describes a memory corruption vulnerability in Qualcomm's IPA (IP Accelerator) statistics processing when no active clients are registered. S...
Jan 6, 2025A buffer overflow vulnerability in GNU objdump's BFD library allows attackers to execute arbitrary code or cause denial of service by processing speci...
Dec 5, 2024This CVE-2024-27407 is a buffer overflow vulnerability in the Linux kernel's NTFS3 filesystem driver, specifically in the mi_enum_attr() function. Att...
May 17, 2024This CVE describes a buffer overflow vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem. Attackers could exploit this to execute ...
Apr 28, 2024This CVE describes a memory corruption vulnerability in the SPS Application's sorter Trusted Application (TA) when requesting public keys. Successful ...
Apr 1, 2024This CVE describes a memory corruption vulnerability in Qualcomm's FM HCI driver when processing IOCTL WRITE requests. Attackers could exploit this to...
Mar 4, 2024This vulnerability allows memory corruption when the Qualcomm resource manager sends fragmented reply messages to the host kernel. Attackers could exp...
Jan 2, 2024This CVE describes a buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when processing WMI commands. Attackers co...
Feb 12, 2023This vulnerability allows memory corruption via buffer overflow when parsing DSF audio file headers with corrupted channel counts in Qualcomm Snapdrag...
Jun 14, 2022This vulnerability in Samsung's eden_runtime HAL service allows attackers to write arbitrary memory and execute code due to improper boundary checking...
Feb 11, 2022This vulnerability allows buffer overflow attacks in Qualcomm Snapdragon VR service due to improper handling of negative data lengths in write request...
Oct 20, 2021This vulnerability allows attackers to execute arbitrary code or cause denial of service via heap overflow in Qualcomm Snapdragon chipsets. It affects...
Sep 9, 2021This vulnerability allows a buffer overflow in Qualcomm Snapdragon Trusted Applications due to missing length validation. Attackers could potentially ...
Jul 13, 2021An integer overflow vulnerability in EVerest EV charging software allows attackers to trigger either infinite loops or stack buffer overflows by sendi...
Jan 21, 2026CVE-2024-31225 is a buffer overflow vulnerability in RIOT OS's _on_rd_init() function that lacks bounds checking when copying data to a static buffer....
May 1, 2024CVE-2023-38671 is a heap buffer overflow vulnerability in the paddle.trace function of PaddlePaddle machine learning framework. This allows attackers ...
Jul 26, 2023An unauthenticated remote attacker can send malicious MQTT messages to trigger buffer overflow vulnerabilities in charging stations compliant with Ger...
Jul 8, 2025A buffer overflow vulnerability in Synology Drive Client's vss service allows remote attackers to crash the client by sending specially crafted data. ...
Sep 26, 2024CVE-2024-39207 is a buffer overflow vulnerability in lua-shmem v1.0-1's shmem_write function that allows attackers to write beyond allocated memory bo...
Jun 27, 2024CVE-2024-37305 is a buffer overflow vulnerability in oqs-provider that handles post-quantum cryptography for OpenSSL 3. Attackers can craft malicious ...
Jun 17, 2024CVE-2024-30259 is a heap buffer overflow vulnerability in FastDDS that allows remote attackers to crash Fast-DDS processes by sending malformed RTPS p...
May 14, 2024About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,147 CVEs classified as CWE-120, with 341 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free