CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,164
Total CVEs
352
Critical
642
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 85
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 40
6 Linux 35
7 Netgear 35
8 Debian 32
9 Fedoraproject 28
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,164)

CVE-2023-43896
7.8

A buffer overflow vulnerability in Macrium Reflect backup software allows attackers to escalate privileges or execute arbitrary code. This affects use...

Oct 10, 2023
CVE-2023-43907
7.8

CVE-2023-43907 is a buffer overflow vulnerability in OptiPNG's GIF processing code that allows attackers to execute arbitrary code or cause denial of ...

Oct 1, 2023
CVE-2023-41064
7.8

This CVE describes a buffer overflow vulnerability in Apple's image processing that allows arbitrary code execution when processing malicious images. ...

Sep 7, 2023
CVE-2023-32379
7.8

A buffer overflow vulnerability in macOS allows malicious applications to execute arbitrary code with kernel privileges. This affects macOS systems be...

Sep 6, 2023
CVE-2023-28209
7.8

This CVE describes a buffer overflow vulnerability in macOS that allows an application to cause system crashes or write to kernel memory. It affects m...

Sep 6, 2023
CVE-2023-28211
7.8

This CVE describes a buffer overflow vulnerability in macOS that allows malicious applications to cause system crashes or write to kernel memory. It a...

Sep 6, 2023
CVE-2023-28213
7.8

This CVE describes a buffer overflow vulnerability in macOS that allows an application to cause system crashes or write to kernel memory. It affects m...

Sep 6, 2023
CVE-2023-28215
7.8

This CVE describes a buffer overflow vulnerability in macOS that allows malicious applications to cause system crashes or write to kernel memory. It a...

Sep 6, 2023
CVE-2023-32356
7.8

This CVE describes a buffer overflow vulnerability in macOS that allows malicious applications to cause system crashes or write to kernel memory. It a...

Sep 6, 2023
CVE-2023-28544
7.8

This vulnerability allows memory corruption in Qualcomm WLAN firmware when sending transmit commands from the host operating system to UTF handlers. A...

Sep 5, 2023
CVE-2023-28560
7.8

This vulnerability allows memory corruption in the WLAN Hardware Abstraction Layer (HAL) when processing devIndex values from untrusted WMI payloads. ...

Sep 5, 2023
CVE-2023-21662
7.8

CVE-2023-21662 is a memory corruption vulnerability in Qualcomm's Core Platform that occurs while printing response buffers in logs. This buffer overf...

Sep 5, 2023
CVE-2023-21664
7.8

This vulnerability allows memory corruption in Qualcomm's Core Platform when printing response buffers in logs. Attackers could potentially execute ar...

Sep 5, 2023
CVE-2023-40031
7.8

Notepad++ versions 8.5.6 and earlier contain a heap buffer overflow vulnerability in the UTF-8/16 conversion function that could allow attackers to ex...

Aug 25, 2023
CVE-2020-21428
7.8

A buffer overflow vulnerability in FreeImage's DDS plugin allows remote attackers to execute arbitrary code by tricking a user or system into processi...

Aug 22, 2023
CVE-2020-21426
7.8

A buffer overflow vulnerability in FreeImage's EXR plugin allows remote attackers to execute arbitrary code by providing a crafted image file. This af...

Aug 22, 2023
CVE-2021-28835
7.8

A buffer overflow vulnerability in XNView allows local attackers to execute arbitrary code by opening a specially crafted GEM bitmap file. This affect...

Aug 11, 2023
CVE-2020-28840
7.8

CVE-2020-28840 is a buffer overflow vulnerability in jhead's jpgfile.c that allows local attackers to execute arbitrary code or cause denial of servic...

Aug 11, 2023
CVE-2020-24222
7.8

A buffer overflow vulnerability in the jfif_decode() function of rockcarry ffjpeg allows local attackers to execute arbitrary code by exploiting memor...

Aug 11, 2023
CVE-2023-29414
7.8

This vulnerability allows local users to escalate privileges by exploiting a buffer overflow in a local function call. Attackers can send specially cr...

Jul 12, 2023
CVE-2023-24851
7.8

This vulnerability allows memory corruption in Qualcomm WLAN Host software when parsing QMI response messages from firmware. Attackers could potential...

Jul 4, 2023
CVE-2023-36377
7.8

A buffer overflow vulnerability in osslsigncode versions 2.3 and earlier allows local attackers to execute arbitrary code by crafting malicious .exe, ...

Jul 3, 2023
CVE-2023-32384
7.8

This CVE describes a buffer overflow vulnerability in Apple's image processing components that could allow arbitrary code execution when processing a ...

Jun 23, 2023
CVE-2023-36243
7.8

CVE-2023-36243 is a buffer overflow vulnerability in FLVMeta v1.2.1 that allows attackers to execute arbitrary code or cause denial of service by expl...

Jun 22, 2023
CVE-2023-31979
7.8

CVE-2023-31979 is a buffer overflow vulnerability in Catdoc v0.95's process_file function that allows attackers to execute arbitrary code or cause den...

May 9, 2023
CVE-2023-27957
7.8

This CVE describes a buffer overflow vulnerability in macOS that could allow arbitrary code execution when processing malicious files. It affects macO...

May 8, 2023
CVE-2023-30257
7.8

This CVE describes a buffer overflow vulnerability in the FiiO M6 audio player's debug component that allows local attackers to escalate privileges to...

May 8, 2023
CVE-2023-29596
7.8

A buffer overflow vulnerability in ByronKnoll Cmix v.19 allows attackers to execute arbitrary code or cause denial of service via the paq8 function. T...

Apr 26, 2023
CVE-2021-33971
7.8

This CVE describes a set of buffer overflow vulnerabilities in Qihoo 360 security software that allow arbitrary code execution. Remote exploitation is...

Apr 19, 2023
CVE-2023-26733
7.8

A buffer overflow vulnerability in tinyTIFF v3.0 allows a local attacker to cause denial of service by exploiting the TinyTiffReader_readNextFrame fun...

Apr 4, 2023
CVE-2022-42431
7.8

This is a local privilege escalation vulnerability in Tesla vehicle systems that allows attackers with initial code execution to gain root privileges....

Mar 29, 2023
CVE-2022-47664
7.8

CVE-2022-47664 is a buffer overflow vulnerability in Libde265's HEVC video decoding function that could allow attackers to execute arbitrary code or c...

Mar 3, 2023
CVE-2023-0996
7.8

This vulnerability allows attackers to exploit a buffer overflow in the strided image data parsing code of the emscripten wrapper for libheif by provi...

Feb 24, 2023
CVE-2021-35129
7.8

This vulnerability allows memory corruption in Bluetooth controllers on Qualcomm Snapdragon chipsets due to improper length validation when processing...

Jun 14, 2022
CVE-2021-35102
7.8

This vulnerability is a buffer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of servic...

Jun 14, 2022
CVE-2022-32981
7.8

A buffer overflow vulnerability exists in the Linux kernel's ptrace system call on 32-bit PowerPC platforms when accessing floating point registers vi...

Jun 10, 2022
CVE-2022-26749
7.8

This is a buffer overflow vulnerability in macOS that allows applications to execute arbitrary code with kernel privileges. It affects macOS Monterey ...

May 26, 2022
CVE-2022-26753
7.8

This is a buffer overflow vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS Montere...

May 26, 2022
CVE-2022-26741
7.8

This is a kernel-level buffer overflow vulnerability in macOS that allows malicious applications to execute arbitrary code with kernel privileges. It ...

May 26, 2022
CVE-2022-30784
7.8

This vulnerability in NTFS-3G allows a specially crafted NTFS filesystem image to trigger heap exhaustion via the ntfs_get_attribute_value function, p...

May 26, 2022
CVE-2022-1735
7.8

CVE-2022-1735 is a classic buffer overflow vulnerability in Vim text editor versions prior to 8.2.4969. Attackers can exploit this by tricking users i...

May 17, 2022
CVE-2022-26259
7.8

A buffer overflow vulnerability in Xiongmai DVR devices allows attackers to cause Denial of Service (DoS) via specially crafted RTSP requests. This af...

Mar 28, 2022
CVE-2022-22819
7.8

This vulnerability allows attackers to execute arbitrary code on affected NXP LPC55S6x microcontrollers by exploiting a buffer overflow during SB2 upd...

Mar 23, 2022
CVE-2021-46064
7.8

IrfanView 4.59 contains a buffer overflow vulnerability in its TIFF image processing function. When a user opens a malicious TIFF file, attackers can ...

Mar 23, 2022
CVE-2022-22634
7.8

This is a buffer overflow vulnerability in Apple's iOS, iPadOS, and tvOS that allows malicious applications to execute arbitrary code with kernel priv...

Mar 18, 2022
CVE-2022-22593
7.8

This CVE describes a buffer overflow vulnerability in Apple operating systems that allows a malicious application to execute arbitrary code with kerne...

Mar 18, 2022
CVE-2022-26981
7.8

CVE-2022-26981 is a buffer overflow vulnerability in Liblouis's compilePassOpcode function that can be triggered when processing translation tables. T...

Mar 13, 2022
CVE-2022-23187
7.8

Adobe Illustrator versions 26.0.3 and earlier contain a buffer overflow vulnerability that allows arbitrary code execution when a user opens a malicio...

Mar 11, 2022
CVE-2022-26490
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's NFC driver (st21nfca). Attackers can exploit this by sending specially crafte...

Mar 6, 2022
CVE-2021-43619
7.8

CVE-2021-43619 is a buffer overflow vulnerability in Trusted Firmware M's Firmware Update partition that allows attackers to overwrite stack memory. T...

Mar 1, 2022

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,164 CVEs classified as CWE-120, with 352 rated critical and 642 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free