CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,173)
This vulnerability allows attackers to execute arbitrary code on affected NXP LPC55S6x microcontrollers by exploiting a buffer overflow during SB2 upd...
Mar 23, 2022IrfanView 4.59 contains a buffer overflow vulnerability in its TIFF image processing function. When a user opens a malicious TIFF file, attackers can ...
Mar 23, 2022This is a buffer overflow vulnerability in Apple's iOS, iPadOS, and tvOS that allows malicious applications to execute arbitrary code with kernel priv...
Mar 18, 2022This CVE describes a buffer overflow vulnerability in Apple operating systems that allows a malicious application to execute arbitrary code with kerne...
Mar 18, 2022CVE-2022-26981 is a buffer overflow vulnerability in Liblouis's compilePassOpcode function that can be triggered when processing translation tables. T...
Mar 13, 2022Adobe Illustrator versions 26.0.3 and earlier contain a buffer overflow vulnerability that allows arbitrary code execution when a user opens a malicio...
Mar 11, 2022This CVE describes a buffer overflow vulnerability in the Linux kernel's NFC driver (st21nfca). Attackers can exploit this by sending specially crafte...
Mar 6, 2022CVE-2021-43619 is a buffer overflow vulnerability in Trusted Firmware M's Firmware Update partition that allows attackers to overwrite stack memory. T...
Mar 1, 2022This buffer overflow vulnerability in Adobe Photoshop allows attackers to execute arbitrary code by tricking users into opening specially crafted mali...
Feb 16, 2022Adobe Illustrator versions 25.4.3 and earlier and 26.0.2 and earlier contain a buffer overflow vulnerability when processing malicious files. This cou...
Feb 16, 2022CVE-2021-30309 is a buffer overflow vulnerability in Qualcomm Snapdragon chipsets where improper validation of QXDM diagnostic command sizes can lead ...
Feb 11, 2022A local buffer overflow vulnerability in HPE FlexNetwork 5130 EL Switch Series allows attackers with local access to potentially execute arbitrary cod...
Feb 4, 2022CVE-2021-46526 is a global buffer overflow vulnerability in Cesanta MJS v2.20.0's JSON parsing functionality that allows attackers to execute arbitrar...
Jan 27, 2022CVE-2021-46513 is a buffer overflow vulnerability in Cesanta MJS JavaScript engine that allows attackers to execute arbitrary code or cause denial of ...
Jan 27, 2022A buffer overflow vulnerability in Gpac's MP4 file parser allows attackers to execute arbitrary code or cause denial of service by providing a special...
Jan 13, 2022This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Qualcomm Snapdragon devices by sending specially ...
Jan 3, 2022This vulnerability allows heap memory corruption due to insufficient input validation when processing HWTC IQ Capture commands in Qualcomm Snapdragon ...
Jan 3, 2022This is a local buffer overflow vulnerability in Miniftpd's ftpproto.c file that allows attackers to execute arbitrary code or crash the service by se...
Nov 4, 2021A buffer overflow vulnerability in Huawei smartphones allows remote code execution when users open malicious images. This affects Huawei smartphone us...
Oct 28, 2021This vulnerability is a buffer overflow in NXP MCUXpresso SDK's USB_HostProcessCallback() function that allows attackers to execute arbitrary code or ...
Oct 25, 2021Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow vulnerability that allows attackers to cause denial of service (DoS) by opening a speciall...
Oct 22, 2021CVE-2020-28963 is a buffer overflow vulnerability in Passcovery ZIP Password Recovery software that allows attackers to execute arbitrary code by expl...
Oct 22, 2021A buffer overflow vulnerability in Adobe Photoshop allows arbitrary code execution when parsing malicious SVG files. Attackers can exploit this by tri...
Sep 27, 2021This is a kernel-level buffer overflow vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kern...
Sep 8, 2021CVE-2021-36075 is a buffer overflow vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious Bridge file. Atta...
Sep 1, 2021This CVE describes a buffer overflow vulnerability in macOS that allows malicious applications to execute arbitrary code with kernel privileges. It af...
Aug 24, 2021This CVE describes a buffer overflow vulnerability in Apple's USD file processing that could allow attackers to crash applications or execute arbitrar...
Aug 24, 2021This CVE-2021-30981 is a buffer overflow vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affect...
Aug 24, 2021This CVE describes a buffer overflow vulnerability in iOS/iPadOS that allows malicious applications to execute arbitrary code with kernel privileges. ...
Aug 24, 2021This CVE describes a buffer overflow vulnerability in Apple's audio file processing components. Attackers can exploit it by crafting malicious audio f...
Aug 24, 2021This vulnerability in TensorFlow allows attackers to trigger heap buffer overflows and segmentation faults by passing non-string data types to dataset...
Aug 12, 2021This vulnerability in the Linux kernel's virtio_console driver allows an untrusted virtual device to supply a buffer length value exceeding the actual...
Aug 7, 2021This CVE describes a buffer overflow vulnerability in Graphviz graph visualization tools that allows remote attackers to execute arbitrary code or cau...
Apr 29, 2021This CVE describes a buffer overflow vulnerability in Adobe Photoshop that allows arbitrary code execution when parsing malicious JSX files. Attackers...
Apr 15, 2021CVE-2021-30184 is a buffer overflow vulnerability in GNU Chess 6.2.7 that allows attackers to execute arbitrary code by providing malicious PGN (Porta...
Apr 7, 2021This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file that triggers a buffer overflow i...
Apr 6, 2021This vulnerability allows attackers to execute arbitrary code or crash applications by tricking users into opening malicious USD (Universal Scene Desc...
Apr 2, 2021This CVE describes a buffer overflow vulnerability in the sniff_channel_order function within ffmpeg's AAC decoder. Attackers can exploit this to exec...
Mar 30, 2021This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting an out-of-bounds write in Qualcomm camera drive...
Feb 22, 2021A buffer overflow vulnerability in HPE Apollo 70 System BMC firmware allows local attackers to execute arbitrary code or cause denial of service. This...
Feb 8, 2021A buffer overflow vulnerability in HPE Apollo 70 System BMC firmware allows local attackers to execute arbitrary code with elevated privileges. This a...
Feb 8, 2021This vulnerability allows local attackers to execute arbitrary code on HPE Apollo 70 System Baseboard Management Controllers through a buffer overflow...
Feb 8, 2021A buffer overflow vulnerability in the Baseboard Management Controller firmware of HPE Apollo 70 Systems allows local attackers to execute arbitrary c...
Feb 8, 2021A buffer overflow vulnerability in the Baseboard Management Controller firmware of HPE Apollo 70 Systems allows local attackers to execute arbitrary c...
Feb 8, 2021CVE-2020-18750 is a buffer overflow vulnerability in pdf2json version 0.69 that allows local users to execute arbitrary code by converting a malicious...
Feb 5, 2021A buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware for HPE Cloudline servers allows local attackers to execute arbi...
Jan 29, 2021A buffer overflow vulnerability in the HPE Cloudline server BMC firmware allows local attackers to execute arbitrary code with elevated privileges. Th...
Jan 29, 2021A local buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers allows authenticated att...
Jan 29, 2021A buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers allows local attackers to exec...
Jan 29, 2021A local buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware for specific HPE Cloudline servers allows authenticated at...
Jan 29, 2021About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,173 CVEs classified as CWE-120, with 359 rated critical and 644 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free