CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,155
Total CVEs
347
Critical
638
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 83
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 40
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,155)

CVE-2020-24474
8.0

A buffer overflow vulnerability in Intel BMC firmware allows authenticated attackers with adjacent network access to potentially escalate privileges o...

Jun 9, 2021
CVE-2024-40427
7.9

A stack buffer overflow vulnerability in PX4-Autopilot v1.14.3 allows attackers to execute arbitrary commands, potentially leading to denial of servic...

Jan 7, 2025
CVE-2023-28741
7.9

A buffer overflow vulnerability in Intel QAT drivers for Windows allows authenticated local users to potentially escalate privileges. This affects sys...

Nov 14, 2023
CVE-2025-47399
7.8

This vulnerability allows attackers to cause memory corruption by sending specially crafted IOCTL calls with invalid parameters to sensor property set...

Feb 2, 2026
CVE-2025-47388
7.8

This CVE describes a memory corruption vulnerability in Qualcomm DSP (Digital Signal Processor) drivers where passing memory pages with unaligned star...

Jan 7, 2026
CVE-2025-47394
7.8

This CVE describes a memory corruption vulnerability in Qualcomm components where incorrect offset calculations during overlapping buffer copy operati...

Jan 7, 2026
CVE-2025-47321
7.8

This vulnerability involves memory corruption when copying packets from Unix domain socket clients, potentially allowing attackers to execute arbitrar...

Dec 18, 2025
CVE-2025-10886
7.8

This CVE describes a memory corruption vulnerability in Autodesk products when parsing malicious MODEL files. Attackers can exploit this to execute ar...

Dec 16, 2025
CVE-2025-10887
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious MODEL files in affected Autodesk products. The ...

Dec 16, 2025
CVE-2025-10889
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPART files in affected Autodesk products. Me...

Dec 16, 2025
CVE-2025-36927
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the Tachyon component. Attackers ca...

Dec 11, 2025
CVE-2025-36928
7.8

This vulnerability in Android's gxp_buffer.h component allows an attacker to write data beyond allocated memory boundaries due to improper bounds chec...

Dec 11, 2025
CVE-2025-36930
7.8

This vulnerability allows local privilege escalation through an out-of-bounds write in the GetHostAddress function of gxp_buffer.h. Attackers can expl...

Dec 11, 2025
CVE-2025-36931
7.8

This vulnerability allows local privilege escalation through an out-of-bounds write in the GetHostAddress function of gxp_buffer.h. Attackers can expl...

Dec 11, 2025
CVE-2025-64182
7.8

This vulnerability in OpenEXR's deprecated Python adapter allows memory corruption when processing malicious EXR files. Attackers can cause crashes or...

Nov 10, 2025
CVE-2025-47341
7.8

This vulnerability allows memory corruption when processing image encoding completion events in Qualcomm components. Attackers could potentially execu...

Oct 9, 2025
CVE-2025-21476
7.8

This vulnerability allows memory corruption during Trusted Virtual Machine handshake parameter passing, potentially enabling arbitrary code execution ...

Sep 24, 2025
CVE-2025-8892
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious PRT files in affected Autodesk products. The me...

Sep 22, 2025
CVE-2025-5048
7.8

This vulnerability allows attackers to execute arbitrary code on AutoCAD systems by tricking users into opening malicious DGN files. The vulnerability...

Aug 15, 2025
CVE-2025-5037
7.8

A memory corruption vulnerability in Autodesk Revit allows arbitrary code execution when processing malicious RFA, RTE, or RVT files. Attackers can ex...

Jul 10, 2025
CVE-2025-27058
7.8

This CVE describes a buffer overflow vulnerability in Qualcomm components where processing packets with excessively large sizes can cause memory corru...

Jul 8, 2025
CVE-2025-27052
7.8

This vulnerability allows memory corruption in the diag component when processing data packets from Unix clients. Attackers could potentially execute ...

Jul 8, 2025
CVE-2025-27043
7.8

This vulnerability allows memory corruption in Qualcomm video firmware when processing manipulated payloads. Attackers could potentially execute arbit...

Jul 8, 2025
CVE-2025-21444
7.8

This CVE describes a buffer overflow vulnerability in Qualcomm's EMAC (Ethernet Media Access Controller) driver where memory corruption occurs while c...

Jul 8, 2025
CVE-2025-5601
7.8

A buffer overflow vulnerability in Wireshark's column handling allows attackers to cause denial of service via packet injection or specially crafted c...

Jun 4, 2025
CVE-2025-46713
7.8

CVE-2025-46713 is an arithmetic overflow vulnerability in Sandboxie's memory allocation subsystem that leads to buffer overflow. This allows attackers...

May 22, 2025
CVE-2025-37803
7.8

A buffer size overflow vulnerability in the Linux kernel's udmabuf driver allows local attackers to cause memory corruption during udmabuf creation. T...

May 8, 2025
CVE-2025-46397
7.8

A buffer overflow vulnerability in xfig's bezier_spline function allows local attackers to execute arbitrary code by manipulating input. This affects ...

Apr 23, 2025
CVE-2025-29625
7.8

A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or crash the application by passing an overly long enviro...

Apr 18, 2025
CVE-2025-1277
7.8

A memory corruption vulnerability in Autodesk applications allows arbitrary code execution when processing malicious PDF files. Attackers can exploit ...

Apr 15, 2025
CVE-2022-49754
7.8

This CVE-2022-49754 is a buffer overflow vulnerability in the Linux kernel's Bluetooth management interface. It allows attackers to write beyond alloc...

Mar 27, 2025
CVE-2025-27835
7.8

A buffer overflow vulnerability in Artifex Ghostscript's glyph-to-Unicode conversion function allows attackers to execute arbitrary code or cause deni...

Mar 25, 2025
CVE-2025-27830
7.8

A buffer overflow vulnerability in Artifex Ghostscript allows attackers to execute arbitrary code or cause denial of service by processing maliciously...

Mar 25, 2025
CVE-2025-27833
7.8

A buffer overflow vulnerability in Artifex Ghostscript allows attackers to execute arbitrary code by providing a specially crafted long TTF font name....

Mar 25, 2025
CVE-2025-27834
7.8

A buffer overflow vulnerability in Artifex Ghostscript allows remote attackers to execute arbitrary code by crafting a malicious PDF document with an ...

Mar 25, 2025
CVE-2025-1430
7.8

This vulnerability allows an attacker to execute arbitrary code on a system by tricking a user into opening a malicious SLDPRT file in Autodesk AutoCA...

Mar 13, 2025
CVE-2025-2017
7.8

A buffer overflow vulnerability in Ashlar-Vellum Cobalt's CO file parser allows remote attackers to execute arbitrary code when users open malicious f...

Mar 11, 2025
CVE-2024-43055
7.8

This CVE describes a memory corruption vulnerability in Qualcomm camera drivers when processing IOCTL calls. Attackers could exploit this to execute a...

Mar 3, 2025
CVE-2025-21780
7.8

This CVE describes a buffer overflow vulnerability in the AMD GPU driver for Linux kernels. A malicious user with local access can exploit this by pro...

Feb 27, 2025
CVE-2022-49267
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's MMC core subsystem where sprintf() was used for sysfs output instead of the s...

Feb 26, 2025
CVE-2022-49058
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's CIFS filesystem driver when handling symbolic links. An attacker could exploi...

Feb 26, 2025
CVE-2024-57509
7.8

A buffer overflow vulnerability in Bento4's mp42avc tool allows local attackers to execute arbitrary code by exploiting the AP4_File::ParseStream func...

Jan 29, 2025
CVE-2024-57510
7.8

A buffer overflow vulnerability in Bento4's mp42avc tool allows local attackers to execute arbitrary code by exploiting the AP4_MemoryByteStream::Writ...

Jan 29, 2025
CVE-2024-0146
7.8

This vulnerability in NVIDIA vGPU software allows a malicious guest virtual machine to cause memory corruption in the Virtual GPU Manager. Successful ...

Jan 28, 2025
CVE-2022-47090
7.8

This vulnerability is a buffer overflow in GPAC MP4box's VVC video parser that occurs when processing specially crafted video files. Attackers could e...

Jan 24, 2025
CVE-2018-9387
7.8

CVE-2018-9387 is an integer overflow vulnerability in Android's mnh-sm.c driver that can trigger a heap overflow, allowing local privilege escalation ...

Jan 18, 2025
CVE-2024-45541
7.8

This vulnerability allows user-space applications to trigger memory corruption through an IOCTL call when reading board data. It affects systems using...

Jan 6, 2025
CVE-2024-45547
7.8

This vulnerability allows memory corruption through a specific IOCTL call when processing FIPS encryption/decryption verification in Qualcomm componen...

Jan 6, 2025
CVE-2024-47032
7.8

This CVE describes a heap buffer overflow vulnerability in Android's lwis_ioctl.c that allows local privilege escalation without user interaction. Att...

Jan 3, 2025
CVE-2024-52060
7.8

This CVE describes a classic buffer overflow vulnerability in RTI Connext Professional services where environment variables can trigger buffer overflo...

Dec 13, 2024

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,155 CVEs classified as CWE-120, with 347 rated critical and 638 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free