CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,160
Total CVEs
349
Critical
641
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 85
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 40
6 Linux 35
7 Netgear 35
8 Debian 32
9 Fedoraproject 28
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,160)

CVE-2024-45541
7.8

This vulnerability allows user-space applications to trigger memory corruption through an IOCTL call when reading board data. It affects systems using...

Jan 6, 2025
CVE-2024-45547
7.8

This vulnerability allows memory corruption through a specific IOCTL call when processing FIPS encryption/decryption verification in Qualcomm componen...

Jan 6, 2025
CVE-2024-47032
7.8

This CVE describes a heap buffer overflow vulnerability in Android's lwis_ioctl.c that allows local privilege escalation without user interaction. Att...

Jan 3, 2025
CVE-2024-52060
7.8

This CVE describes a classic buffer overflow vulnerability in RTI Connext Professional services where environment variables can trigger buffer overflo...

Dec 13, 2024
CVE-2024-29645
7.8

A buffer overflow vulnerability in radare2 v5.8.8 allows attackers to execute arbitrary code by exploiting the parse_die function. This affects users ...

Dec 2, 2024
CVE-2024-44307
7.8

A buffer overflow vulnerability in macOS allows malicious applications to execute arbitrary code with kernel privileges. This affects macOS systems be...

Nov 20, 2024
CVE-2024-50282
7.8

This CVE describes a buffer overflow vulnerability in the AMD GPU driver for the Linux kernel. An attacker could exploit this to execute arbitrary cod...

Nov 19, 2024
CVE-2024-46952
7.8

This vulnerability in Artifex Ghostscript allows buffer overflow during PDF XRef stream handling, potentially enabling remote code execution. It affec...

Nov 10, 2024
CVE-2024-35422
7.8

CVE-2024-35422 is a heap buffer overflow vulnerability in vmir's WebAssembly parser that allows attackers to execute arbitrary code or cause denial of...

Nov 8, 2024
CVE-2024-50131
7.8

This CVE-2024-50131 is a buffer overflow vulnerability in the Linux kernel's tracing subsystem where string length validation fails to account for the...

Nov 5, 2024
CVE-2024-38423
7.8

This vulnerability allows memory corruption during GPU page table switching in Qualcomm GPU drivers. Attackers could potentially execute arbitrary cod...

Nov 4, 2024
CVE-2024-38409
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's station LL statistic handling that could allow attackers to execute arbitrary code ...

Nov 4, 2024
CVE-2024-9997
7.8

A memory corruption vulnerability in Autodesk AutoCAD's DWG file parser (acdb25.dll) allows attackers to crash applications, leak sensitive data, or e...

Oct 29, 2024
CVE-2024-8592
7.8

A memory corruption vulnerability in Autodesk AutoCAD's CATPART file parser allows attackers to crash the application, leak sensitive data, or execute...

Oct 29, 2024
CVE-2022-48948
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's USB gadget UVC driver. It allows attackers to write 4 bytes beyond the alloca...

Oct 21, 2024
CVE-2024-49996
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's CIFS filesystem driver when parsing NFS reparse points. An attacker could exp...

Oct 21, 2024
CVE-2024-49869
7.8

This CVE describes a buffer overflow detection issue in the Linux kernel's btrfs send functionality. The vulnerability occurs when copying path names ...

Oct 21, 2024
CVE-2024-33054
7.8

This vulnerability allows memory corruption during the handshake process between Primary and Trusted Virtual Machines in Qualcomm platforms. Attackers...

Sep 2, 2024
CVE-2024-33042
7.8

CVE-2024-33042 is a memory corruption vulnerability in Qualcomm chipsets that occurs when the Alternative Frequency offset value is set to 255. This c...

Sep 2, 2024
CVE-2024-40902
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's JFS filesystem when handling invalid extended attributes (xattrs). An attacke...

Jul 12, 2024
CVE-2024-23368
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that could allow attackers to execute arbitrary code...

Jul 1, 2024
CVE-2024-39291
7.8

This CVE describes a buffer overflow vulnerability in the AMD GPU driver within the Linux kernel. The vulnerability could allow local attackers to exe...

Jun 24, 2024
CVE-2021-47609
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's SCPI genpd driver. An attacker could exploit this to cause a kernel panic or ...

Jun 19, 2024
CVE-2021-47485
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's InfiniBand driver (qib). Attackers with local access can exploit integer over...

May 22, 2024
CVE-2024-27045
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's AMD display driver. An attacker could exploit this to cause kernel memory cor...

May 1, 2024
CVE-2024-26936
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's ksmbd SMB server module. Attackers could exploit this by sending specially cr...

May 1, 2024
CVE-2022-48657
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's arm64 topology subsystem. The overflow occurs when converting CPU frequency...

Apr 28, 2024
CVE-2023-50008
7.8

CVE-2023-50008 is a buffer overflow vulnerability in FFmpeg's colorcorrect filter that allows attackers to cause memory corruption through improper me...

Apr 19, 2024
CVE-2023-50010
7.8

This CVE describes a buffer over-read vulnerability in FFmpeg's gradfun filter SSE2 optimization. Attackers can exploit this to read memory beyond all...

Apr 19, 2024
CVE-2023-51793
7.8

A buffer overflow vulnerability in FFmpeg's image_copy_plane function allows local attackers to execute arbitrary code. This affects systems running v...

Apr 19, 2024
CVE-2023-51798
7.8

This CVE describes a buffer overflow vulnerability in FFmpeg's minterpolate filter that allows a local attacker to execute arbitrary code via a floati...

Apr 19, 2024
CVE-2024-26797
7.8

This CVE describes a buffer overflow vulnerability in the AMD display driver within the Linux kernel. An attacker could exploit this to cause kernel c...

Apr 4, 2024
CVE-2023-6175
7.8

A buffer overflow vulnerability in Wireshark's NetScreen file parser allows attackers to cause a denial of service by providing a specially crafted ca...

Mar 26, 2024
CVE-2024-28569
7.8

A buffer overflow vulnerability in FreeImage v3.19.0 allows local attackers to execute arbitrary code by exploiting the Imf_2_2::Xdr::read() function ...

Mar 20, 2024
CVE-2023-52612
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's crypto scomp subsystem. Attackers could exploit this to write beyond allocate...

Mar 18, 2024
CVE-2023-52614
7.8

A buffer overflow vulnerability in the Linux kernel's devfreq subsystem allows local attackers to write beyond allocated memory boundaries. This affec...

Mar 18, 2024
CVE-2024-23286
7.8

A buffer overflow vulnerability in Apple's image processing components allows arbitrary code execution when processing malicious images. This affects ...

Mar 8, 2024
CVE-2024-20723
7.8

A buffer overflow vulnerability in Substance3D Painter versions 9.1.1 and earlier allows attackers to execute arbitrary code by tricking users into op...

Feb 15, 2024
CVE-2024-25165
7.8

A global buffer overflow vulnerability in SWFTools v0.9.2 allows attackers to execute arbitrary code or cause denial of service by processing maliciou...

Feb 14, 2024
CVE-2023-38583
7.8

This CVE describes a stack-based buffer overflow vulnerability in GTKWave's LXT2 file parser. Attackers can craft malicious .lxt2 files that, when ope...

Jan 8, 2024
CVE-2023-33085
7.8

This vulnerability involves memory corruption in Qualcomm wearable devices while processing data from the Always-On (AON) subsystem. Attackers could p...

Jan 2, 2024
CVE-2023-33087
7.8

This vulnerability involves memory corruption in Qualcomm's Core component while processing RX intent requests, potentially allowing attackers to exec...

Dec 5, 2023
CVE-2023-33017
7.8

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices wi...

Dec 5, 2023
CVE-2023-28546
7.8

This vulnerability allows memory corruption in Qualcomm's SPS application when exporting public keys in the sorter TA. Attackers could potentially exe...

Dec 5, 2023
CVE-2023-46587
7.8

A buffer overflow vulnerability in XnView Classic v2.51.5 allows local attackers to execute arbitrary code by opening a specially crafted TIF file. Th...

Oct 27, 2023
CVE-2023-43250
7.8

XNSoft Nconvert 7.136 contains a buffer overflow vulnerability that allows attackers to cause denial of service or potentially execute arbitrary code ...

Oct 18, 2023
CVE-2023-43896
7.8

A buffer overflow vulnerability in Macrium Reflect backup software allows attackers to escalate privileges or execute arbitrary code. This affects use...

Oct 10, 2023
CVE-2023-43907
7.8

CVE-2023-43907 is a buffer overflow vulnerability in OptiPNG's GIF processing code that allows attackers to execute arbitrary code or cause denial of ...

Oct 1, 2023
CVE-2023-41064
7.8

This CVE describes a buffer overflow vulnerability in Apple's image processing that allows arbitrary code execution when processing malicious images. ...

Sep 7, 2023
CVE-2023-32379
7.8

A buffer overflow vulnerability in macOS allows malicious applications to execute arbitrary code with kernel privileges. This affects macOS systems be...

Sep 6, 2023

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,160 CVEs classified as CWE-120, with 349 rated critical and 641 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free