CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,151)
CVE-2024-39207 is a buffer overflow vulnerability in lua-shmem v1.0-1's shmem_write function that allows attackers to write beyond allocated memory bo...
Jun 27, 2024CVE-2024-37305 is a buffer overflow vulnerability in oqs-provider that handles post-quantum cryptography for OpenSSL 3. Attackers can craft malicious ...
Jun 17, 2024CVE-2024-30259 is a heap buffer overflow vulnerability in FastDDS that allows remote attackers to crash Fast-DDS processes by sending malformed RTPS p...
May 14, 2024A buffer overflow vulnerability in Trellix Agent (TA) for Linux and macOS allows local users to gain root privileges or cause denial of service throug...
Jan 9, 2024This vulnerability is a heap buffer overflow in the paddle.repeat_interleave function of PaddlePaddle, a deep learning framework. Attackers can exploi...
Jan 3, 2024A stack overflow vulnerability in paddle.searchsorted function in PaddlePaddle allows attackers to cause denial of service or potentially execute arbi...
Jan 3, 2024A stack overflow vulnerability in the paddle.linalg.lu_unpack function in PaddlePaddle allows attackers to cause denial of service or potentially exec...
Jan 3, 2024A buffer overflow vulnerability in Intel Server Board BMC firmware allows privileged users with local access to escalate privileges. This affects serv...
May 10, 2023This is a buffer overflow vulnerability in Parallels Desktop's HDAudio virtual device that allows local attackers with high-privileged code execution ...
Jul 15, 2022This vulnerability affects multiple Siemens SCALANCE industrial network switches. An unauthenticated remote attacker can send specially crafted HTTP r...
Jul 12, 2022A local buffer overflow vulnerability in McAfee Data Loss Prevention Endpoint for Windows allows attackers to execute arbitrary code with elevated pri...
Sep 17, 2021A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all Qsync Cen...
Feb 11, 2026A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all QNAP Qsyn...
Feb 11, 2026A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...
Feb 11, 2026A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects QNAP...
Jan 2, 2026A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...
Jan 2, 2026A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...
Jan 2, 2026A buffer overflow vulnerability in Dahua products allows attackers to send specially crafted packets that could cause service crashes or potentially e...
Jul 23, 2025A buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the Se...
Jul 3, 2025This vulnerability allows remote attackers to execute arbitrary code on SunGrow WiNet-SV200 devices by exploiting a stack-based buffer overflow during...
Jan 24, 2025This CVE describes a buffer overflow vulnerability in U-Boot's DHCP client implementation that allows an attacker on the local network to leak 4-32 by...
Aug 23, 2024A buffer overflow vulnerability in DCMTK v3.6.8 allows attackers to execute arbitrary code via the EctEnhancedCT method component. This affects system...
Jun 28, 2024A buffer overflow vulnerability in libndp allows local attackers to crash or potentially execute arbitrary code on systems running NetworkManager by s...
May 31, 2024A buffer overflow vulnerability in Silicon Labs 500 Series Z-Wave devices could allow attackers to cause denial of service or potentially execute arbi...
May 7, 2024CVE-2023-43887 is a buffer overflow vulnerability in Libde265 v1.0.12's pic_parameter_set::dump function, triggered by malicious num_tile_columns and ...
Nov 22, 2023This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Telit Cinterion EHS5/6/8 cellular modules by sending specially...
Nov 9, 2023This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with pri...
Mar 1, 2023CVE-2023-22753 is a critical buffer overflow vulnerability in Aruba networking devices that allows unauthenticated attackers to execute arbitrary code...
Mar 1, 2023This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with pri...
Mar 1, 2023Rsyslog's TCP syslog reception modules contain a heap buffer overflow vulnerability when octet-counted framing is used. This can cause segmentation fa...
May 6, 2022This vulnerability allows remote attackers to execute arbitrary code on affected Sealevel SeaConnect 370W devices by sending specially crafted MQTT me...
Feb 4, 2022A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...
Jan 14, 2022A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...
Jan 14, 2022A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...
Jan 14, 2022This CVE describes a stack buffer overflow vulnerability in QNAP Surveillance Station that allows attackers to execute arbitrary code on affected NAS ...
Dec 29, 2021A buffer overflow vulnerability in libheif's color conversion function allows attackers to cause denial of service or information disclosure by proces...
Nov 3, 2021A buffer overflow vulnerability in Apple operating systems allows attackers in privileged network positions to execute arbitrary code. This affects ma...
Aug 24, 2021This vulnerability allows remote attackers to execute arbitrary code on affected TP-Link routers via a buffer overflow in the HTTP daemon. Attackers c...
Apr 12, 2021A buffer overflow vulnerability in ZeroMQ versions before 4.3.3 allows remote attackers to write arbitrary data when CURVE/ZAP authentication is disab...
Apr 1, 2021CVE-2020-8625 is a buffer overflow vulnerability in BIND DNS servers that affects systems configured with GSS-TSIG features. Exploitation could lead t...
Feb 17, 2021This vulnerability allows remote attackers to execute arbitrary code or escalate privileges on affected Android devices through an out-of-bounds write...
Dec 11, 2025This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers that allows attackers to execute arbitrary code by sending specially cra...
Feb 28, 2025This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers, caused by improper input validation of the pppoe_dns1 parameter in the ...
Feb 28, 2025This buffer overflow vulnerability in TOTOlink A3002R routers allows attackers to execute arbitrary code by sending specially crafted requests to the ...
Feb 28, 2025This vulnerability allows authenticated attackers to execute arbitrary code as root on TP-Link TL-WR940N V3/V4 routers via buffer overflow in DNS serv...
Jan 9, 2025This vulnerability allows authenticated users to exploit buffer overflows in DrayTek Vigor3910 devices by sending specially crafted POST requests to v...
Oct 3, 2024CVE-2020-7877 is a buffer overflow vulnerability in ZOOK remote administration tool that allows attackers to execute arbitrary commands by sending a s...
Sep 7, 2021A buffer overflow vulnerability in Intel BMC firmware allows authenticated attackers with adjacent network access to potentially escalate privileges o...
Jun 9, 2021A stack buffer overflow vulnerability in PX4-Autopilot v1.14.3 allows attackers to execute arbitrary commands, potentially leading to denial of servic...
Jan 7, 2025A buffer overflow vulnerability in Intel QAT drivers for Windows allows authenticated local users to potentially escalate privileges. This affects sys...
Nov 14, 2023About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,151 CVEs classified as CWE-120, with 344 rated critical and 637 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free