CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,147
Total CVEs
341
Critical
636
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 82
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,147)

CVE-2021-30707
8.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted audio file. It affects Apple devices running macOS, tvOS, watch...

Sep 8, 2021
CVE-2021-28580
8.8

CVE-2021-28580 is a buffer overflow vulnerability in Adobe Medium versions 2.4.5.331 and earlier that allows remote code execution when a user opens a...

Sep 8, 2021
CVE-2021-38111
8.8

This vulnerability allows remote attackers to execute arbitrary code on DEF CON 27 badges by sending specially crafted oversized packets via the NFMI ...

Aug 4, 2021
CVE-2015-2098
8.8

CVE-2015-2098 is a critical stack-based buffer overflow vulnerability in WebGate eDVR Manager that allows remote attackers to execute arbitrary code o...

Jul 22, 2021
CVE-2021-34828
8.8

This is a buffer overflow vulnerability in D-Link DAP-1330 routers that allows network-adjacent attackers to execute arbitrary code without authentica...

Jul 15, 2021
CVE-2021-22129
8.8

This buffer overflow vulnerability in FortiMail allows authenticated webmail users to execute arbitrary code via crafted HTTP requests. It affects For...

Jul 9, 2021
CVE-2021-0101
8.8

A buffer overflow vulnerability in the BMC firmware for Intel Server Board M10JNP2SB allows unauthenticated attackers with adjacent network access to ...

Jun 9, 2021
CVE-2021-22908
8.8

A buffer overflow vulnerability in Pulse Connect Secure's Windows File Resource Profiles allows authenticated users with SMB share browsing privileges...

May 27, 2021
CVE-2020-22015
8.8

This buffer overflow vulnerability in FFmpeg's MOV file handling allows attackers to execute arbitrary code, cause denial of service, or leak sensitiv...

May 26, 2021
CVE-2020-24020
8.8

This CVE describes a buffer overflow vulnerability in FFmpeg's DNN module that allows remote attackers to execute arbitrary code by exploiting imprope...

May 26, 2021
CVE-2021-25328
8.8

This vulnerability allows an authenticated attacker to exploit a buffer overflow in the Skyworth RN510 router's web interface. By sending a specially ...

Apr 9, 2021
CVE-2021-30123
8.8

CVE-2021-30123 is a buffer overflow vulnerability in FFmpeg's libavcodec library that allows remote attackers to execute arbitrary code by providing a...

Apr 7, 2021
CVE-2021-25144
8.8

A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service. This affe...

Mar 29, 2021
CVE-2020-36152
8.8

CVE-2020-36152 is a buffer overflow vulnerability in the readDataVar function of libmysofa's hdf/dataobject.c. Attackers can exploit this by providing...

Feb 8, 2021
CVE-2025-20222
8.6

This vulnerability allows unauthenticated remote attackers to cause a denial of service by sending specially crafted IPv6 packets over IPsec VPN conne...

Aug 14, 2025
CVE-2025-20115
8.6

A memory corruption vulnerability in Cisco IOS XR's BGP confederation implementation allows unauthenticated remote attackers to cause denial of servic...

Mar 12, 2025
CVE-2024-52063
8.6

This CVE describes a classic buffer overflow vulnerability in RTI Connext Professional's Core Libraries and Routing Service. Attackers can exploit thi...

Dec 13, 2024
CVE-2023-20189
8.6

Multiple vulnerabilities in Cisco Small Business Series Switches web interface allow unauthenticated remote attackers to cause denial of service or ex...

May 18, 2023
CVE-2023-20158
8.6

This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to execute arbitrary code with root privileges or c...

May 18, 2023
CVE-2023-20160
8.6

This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to cause denial of service or execute arbitrary cod...

May 18, 2023
CVE-2023-20162
8.6

Multiple vulnerabilities in Cisco Small Business Series Switches web interface allow unauthenticated remote attackers to cause denial of service or ex...

May 18, 2023
CVE-2023-20024
8.6

This vulnerability in Cisco Small Business Series Switches allows unauthenticated remote attackers to execute arbitrary code with root privileges or c...

May 18, 2023
CVE-2023-20156
8.6

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges or cause denial of service on affected Cisco...

May 18, 2023
CVE-2021-21282
8.6

CVE-2021-21282 is a buffer overflow vulnerability in Contiki-NG's RPL implementations when operating in source-routing mode. Attackers can exploit thi...

Jun 18, 2021
CVE-2022-24754
8.5

CVE-2022-24754 is a stack-buffer overflow vulnerability in PJSIP multimedia communication library that affects users accepting hashed digest credentia...

Mar 11, 2022
CVE-2021-1493
8.5

This vulnerability allows authenticated remote attackers to trigger a buffer overflow in Cisco ASA and FTD software web services interface by sending ...

Apr 29, 2021
CVE-2025-49495
8.4

A buffer overflow vulnerability in the WiFi driver of Samsung Exynos 1380, 1480, 2400, and 1580 mobile processors allows attackers to execute arbitrar...

Jan 5, 2026
CVE-2025-53966
8.4

A buffer overflow vulnerability in Samsung Exynos mobile processors allows attackers to execute arbitrary code or cause denial of service by sending s...

Jan 5, 2026
CVE-2025-25723
8.4

A buffer overflow vulnerability in GPAC version 2.5 allows local attackers to execute arbitrary code on affected systems. This affects systems running...

Feb 28, 2025
CVE-2024-21464
8.4

This CVE describes a memory corruption vulnerability in Qualcomm's IPA (IP Accelerator) statistics processing when no active clients are registered. S...

Jan 6, 2025
CVE-2024-53589
8.4

A buffer overflow vulnerability in GNU objdump's BFD library allows attackers to execute arbitrary code or cause denial of service by processing speci...

Dec 5, 2024
CVE-2024-27407
8.4

This CVE-2024-27407 is a buffer overflow vulnerability in the Linux kernel's NTFS3 filesystem driver, specifically in the mi_enum_attr() function. Att...

May 17, 2024
CVE-2024-26927
8.4

This CVE describes a buffer overflow vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem. Attackers could exploit this to execute ...

Apr 28, 2024
CVE-2023-28547
8.4

This CVE describes a memory corruption vulnerability in the SPS Application's sorter Trusted Application (TA) when requesting public keys. Successful ...

Apr 1, 2024
CVE-2023-43540
8.4

This CVE describes a memory corruption vulnerability in Qualcomm's FM HCI driver when processing IOCTL WRITE requests. Attackers could exploit this to...

Mar 4, 2024
CVE-2023-33113
8.4

This vulnerability allows memory corruption when the Qualcomm resource manager sends fragmented reply messages to the host kernel. Attackers could exp...

Jan 2, 2024
CVE-2022-33277
8.4

This CVE describes a buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when processing WMI commands. Attackers co...

Feb 12, 2023
CVE-2022-22082
8.4

This vulnerability allows memory corruption via buffer overflow when parsing DSF audio file headers with corrupted channel counts in Qualcomm Snapdrag...

Jun 14, 2022
CVE-2022-23428
8.4

This vulnerability in Samsung's eden_runtime HAL service allows attackers to write arbitrary memory and execute code due to improper boundary checking...

Feb 11, 2022
CVE-2021-1983
8.4

This vulnerability allows buffer overflow attacks in Qualcomm Snapdragon VR service due to improper handling of negative data lengths in write request...

Oct 20, 2021
CVE-2021-30295
8.4

This vulnerability allows attackers to execute arbitrary code or cause denial of service via heap overflow in Qualcomm Snapdragon chipsets. It affects...

Sep 9, 2021
CVE-2021-1889
8.4

This vulnerability allows a buffer overflow in Qualcomm Snapdragon Trusted Applications due to missing length validation. Attackers could potentially ...

Jul 13, 2021
CVE-2025-68137
8.3

An integer overflow vulnerability in EVerest EV charging software allows attackers to trigger either infinite loops or stack buffer overflows by sendi...

Jan 21, 2026
CVE-2024-31225
8.3

CVE-2024-31225 is a buffer overflow vulnerability in RIOT OS's _on_rd_init() function that lacks bounds checking when copying data to a static buffer....

May 1, 2024
CVE-2023-38671
8.3

CVE-2023-38671 is a heap buffer overflow vulnerability in the paddle.trace function of PaddlePaddle machine learning framework. This allows attackers ...

Jul 26, 2023
CVE-2025-24003
8.2

An unauthenticated remote attacker can send malicious MQTT messages to trigger buffer overflow vulnerabilities in charging stations compliant with Ger...

Jul 8, 2025
CVE-2023-52946
8.2

A buffer overflow vulnerability in Synology Drive Client's vss service allows remote attackers to crash the client by sending specially crafted data. ...

Sep 26, 2024
CVE-2024-39207
8.2

CVE-2024-39207 is a buffer overflow vulnerability in lua-shmem v1.0-1's shmem_write function that allows attackers to write beyond allocated memory bo...

Jun 27, 2024
CVE-2024-37305
8.2

CVE-2024-37305 is a buffer overflow vulnerability in oqs-provider that handles post-quantum cryptography for OpenSSL 3. Attackers can craft malicious ...

Jun 17, 2024
CVE-2024-30259
8.2

CVE-2024-30259 is a heap buffer overflow vulnerability in FastDDS that allows remote attackers to crash Fast-DDS processes by sending malformed RTPS p...

May 14, 2024

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,147 CVEs classified as CWE-120, with 341 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free