CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,151
Total CVEs
344
Critical
637
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 83
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 40
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,151)

CVE-2024-39207
8.2

CVE-2024-39207 is a buffer overflow vulnerability in lua-shmem v1.0-1's shmem_write function that allows attackers to write beyond allocated memory bo...

Jun 27, 2024
CVE-2024-37305
8.2

CVE-2024-37305 is a buffer overflow vulnerability in oqs-provider that handles post-quantum cryptography for OpenSSL 3. Attackers can craft malicious ...

Jun 17, 2024
CVE-2024-30259
8.2

CVE-2024-30259 is a heap buffer overflow vulnerability in FastDDS that allows remote attackers to crash Fast-DDS processes by sending malformed RTPS p...

May 14, 2024
CVE-2024-0213
8.2

A buffer overflow vulnerability in Trellix Agent (TA) for Linux and macOS allows local users to gain root privileges or cause denial of service throug...

Jan 9, 2024
CVE-2023-52309
8.2

This vulnerability is a heap buffer overflow in the paddle.repeat_interleave function of PaddlePaddle, a deep learning framework. Attackers can exploi...

Jan 3, 2024
CVE-2023-52304
8.2

A stack overflow vulnerability in paddle.searchsorted function in PaddlePaddle allows attackers to cause denial of service or potentially execute arbi...

Jan 3, 2024
CVE-2023-52307
8.2

A stack overflow vulnerability in the paddle.linalg.lu_unpack function in PaddlePaddle allows attackers to cause denial of service or potentially exec...

Jan 3, 2024
CVE-2023-22661
8.2

A buffer overflow vulnerability in Intel Server Board BMC firmware allows privileged users with local access to escalate privileges. This affects serv...

May 10, 2023
CVE-2021-34987
8.2

This is a buffer overflow vulnerability in Parallels Desktop's HDAudio virtual device that allows local attackers with high-privileged code execution ...

Jul 15, 2022
CVE-2022-26648
8.2

This vulnerability affects multiple Siemens SCALANCE industrial network switches. An unauthenticated remote attacker can send specially crafted HTTP r...

Jul 12, 2022
CVE-2021-31844
8.2

A local buffer overflow vulnerability in McAfee Data Loss Prevention Endpoint for Windows allows attackers to execute arbitrary code with elevated pri...

Sep 17, 2021
CVE-2025-52869
8.1

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all Qsync Cen...

Feb 11, 2026
CVE-2025-48723
8.1

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all QNAP Qsyn...

Feb 11, 2026
CVE-2025-48725
8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Feb 11, 2026
CVE-2025-52863
8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects QNAP...

Jan 2, 2026
CVE-2025-52864
8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2, 2026
CVE-2025-52872
8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2, 2026
CVE-2025-31700
8.1

A buffer overflow vulnerability in Dahua products allows attackers to send specially crafted packets that could cause service crashes or potentially e...

Jul 23, 2025
CVE-2025-50258
8.1

A buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the Se...

Jul 3, 2025
CVE-2024-50697
8.1

This vulnerability allows remote attackers to execute arbitrary code on SunGrow WiNet-SV200 devices by exploiting a stack-based buffer overflow during...

Jan 24, 2025
CVE-2024-42040
8.1

This CVE describes a buffer overflow vulnerability in U-Boot's DHCP client implementation that allows an attacker on the local network to leak 4-32 by...

Aug 23, 2024
CVE-2024-27628
8.1

A buffer overflow vulnerability in DCMTK v3.6.8 allows attackers to execute arbitrary code via the EctEnhancedCT method component. This affects system...

Jun 28, 2024
CVE-2024-5564
8.1

A buffer overflow vulnerability in libndp allows local attackers to crash or potentially execute arbitrary code on systems running NetworkManager by s...

May 31, 2024
CVE-2024-22472
8.1

A buffer overflow vulnerability in Silicon Labs 500 Series Z-Wave devices could allow attackers to cause denial of service or potentially execute arbi...

May 7, 2024
CVE-2023-43887
8.1

CVE-2023-43887 is a buffer overflow vulnerability in Libde265 v1.0.12's pic_parameter_set::dump function, triggered by malicious num_tile_columns and ...

Nov 22, 2023
CVE-2023-47610
8.1

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Telit Cinterion EHS5/6/8 cellular modules by sending specially...

Nov 9, 2023
CVE-2023-22757
8.1

This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with pri...

Mar 1, 2023
CVE-2023-22753
8.1

CVE-2023-22753 is a critical buffer overflow vulnerability in Aruba networking devices that allows unauthenticated attackers to execute arbitrary code...

Mar 1, 2023
CVE-2023-22755
8.1

This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with pri...

Mar 1, 2023
CVE-2022-24903
8.1

Rsyslog's TCP syslog reception modules contain a heap buffer overflow vulnerability when octet-counted framing is used. This can cause segmentation fa...

May 6, 2022
CVE-2021-21969
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Sealevel SeaConnect 370W devices by sending specially crafted MQTT me...

Feb 4, 2022
CVE-2021-38682
8.1

A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...

Jan 14, 2022
CVE-2021-38690
8.1

A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...

Jan 14, 2022
CVE-2021-38692
8.1

A stack buffer overflow vulnerability in QNAP's QVR Elite, QVR Pro, and QVR Guard software allows attackers to execute arbitrary code on affected devi...

Jan 14, 2022
CVE-2021-38687
8.1

This CVE describes a stack buffer overflow vulnerability in QNAP Surveillance Station that allows attackers to execute arbitrary code on affected NAS ...

Dec 29, 2021
CVE-2020-23109
8.1

A buffer overflow vulnerability in libheif's color conversion function allows attackers to cause denial of service or information disclosure by proces...

Nov 3, 2021
CVE-2021-30993
8.1

A buffer overflow vulnerability in Apple operating systems allows attackers in privileged network positions to execute arbitrary code. This affects ma...

Aug 24, 2021
CVE-2021-29302
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected TP-Link routers via a buffer overflow in the HTTP daemon. Attackers c...

Apr 12, 2021
CVE-2021-20235
8.1

A buffer overflow vulnerability in ZeroMQ versions before 4.3.3 allows remote attackers to write arbitrary data when CURVE/ZAP authentication is disab...

Apr 1, 2021
CVE-2020-8625
8.1

CVE-2020-8625 is a buffer overflow vulnerability in BIND DNS servers that affects systems configured with GSS-TSIG features. Exploitation could lead t...

Feb 17, 2021
CVE-2025-36924
8.0

This vulnerability allows remote attackers to execute arbitrary code or escalate privileges on affected Android devices through an out-of-bounds write...

Dec 11, 2025
CVE-2025-25610
8.0

This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers that allows attackers to execute arbitrary code by sending specially cra...

Feb 28, 2025
CVE-2025-25635
8.0

This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers, caused by improper input validation of the pppoe_dns1 parameter in the ...

Feb 28, 2025
CVE-2025-25609
8.0

This buffer overflow vulnerability in TOTOlink A3002R routers allows attackers to execute arbitrary code by sending specially crafted requests to the ...

Feb 28, 2025
CVE-2024-54887
8.0

This vulnerability allows authenticated attackers to execute arbitrary code as root on TP-Link TL-WR940N V3/V4 routers via buffer overflow in DNS serv...

Jan 9, 2025
CVE-2024-41588
8.0

This vulnerability allows authenticated users to exploit buffer overflows in DrayTek Vigor3910 devices by sending specially crafted POST requests to v...

Oct 3, 2024
CVE-2020-7877
8.0

CVE-2020-7877 is a buffer overflow vulnerability in ZOOK remote administration tool that allows attackers to execute arbitrary commands by sending a s...

Sep 7, 2021
CVE-2020-24474
8.0

A buffer overflow vulnerability in Intel BMC firmware allows authenticated attackers with adjacent network access to potentially escalate privileges o...

Jun 9, 2021
CVE-2024-40427
7.9

A stack buffer overflow vulnerability in PX4-Autopilot v1.14.3 allows attackers to execute arbitrary commands, potentially leading to denial of servic...

Jan 7, 2025
CVE-2023-28741
7.9

A buffer overflow vulnerability in Intel QAT drivers for Windows allows authenticated local users to potentially escalate privileges. This affects sys...

Nov 14, 2023

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,151 CVEs classified as CWE-120, with 344 rated critical and 637 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free