CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,179
Total CVEs
360
Critical
649
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 85
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 42
6 Netgear 35
7 Linux 35
8 Debian 32
9 Fedoraproject 28
10 Google 21

All Buffer Copy without Size Check CVEs (1,179)

CVE-2021-25138
7.8

A local buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers allows authenticated att...

Jan 29, 2021
CVE-2021-25126
7.8

A buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers allows local attackers to exec...

Jan 29, 2021
CVE-2021-25130
7.8

A local buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware for specific HPE Cloudline servers allows authenticated at...

Jan 29, 2021
CVE-2021-25132
7.8

A buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers allows local attackers to exec...

Jan 29, 2021
CVE-2021-25123
7.8

This CVE describes a local buffer overflow vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers. It a...

Jan 29, 2021
CVE-2018-8726
7.8

CVE-2018-8726 is a buffer overflow vulnerability in K7Antivirus Premium's K7TSMngr.exe component that allows local attackers to execute arbitrary code...

Jan 11, 2021
CVE-2018-9333
7.8

CVE-2018-9333 is a buffer overflow vulnerability in K7AntiVirus Premium's K7TSMngr.exe component that allows local attackers to execute arbitrary code...

Jan 11, 2021
CVE-2020-9972
7.8

This vulnerability allows arbitrary code execution or application crashes when processing malicious USD files on Apple devices. It affects iOS and iPa...

Dec 8, 2020
CVE-2020-4701
7.8

CVE-2020-4701 is a buffer overflow vulnerability in IBM DB2 that allows a local attacker to execute arbitrary code with root privileges. This affects ...

Nov 19, 2020
CVE-2020-3678
7.8

This CVE describes a buffer overflow vulnerability in Qualcomm Snapdragon chipsets where improper API usage during UIE initialization could allow memo...

Nov 2, 2020
CVE-2026-20100
7.7

This vulnerability allows authenticated remote attackers with VPN access to cause Cisco ASA/FTD devices to crash and reload by sending specially craft...

Mar 4, 2026
CVE-2023-52080
7.7

This vulnerability in IEIT NF5280M6 server UEFI firmware allows attackers with local NVRAM variable access to exploit a pool overflow via improper gRT...

Apr 29, 2024
CVE-2023-49287
7.7

CVE-2023-49287 is a buffer overflow vulnerability in TinyDir's tinydir_file_open() function that could allow attackers to execute arbitrary code or cr...

Dec 4, 2023
CVE-2025-9557
7.6

CVE-2025-9557 is a buffer overflow vulnerability in Zephyr RTOS that allows attackers to write beyond allocated memory boundaries. This can lead to ar...

Nov 26, 2025
CVE-2025-9558
7.6

CVE-2025-9558 is a buffer overflow vulnerability in Zephyr RTOS's Bluetooth provisioning code that allows attackers to write data beyond allocated mem...

Nov 26, 2025
CVE-2023-4263
7.6

A buffer overflow vulnerability exists in the Zephyr RTOS IEEE 802.15.4 nRF 15.4 driver, allowing attackers to execute arbitrary code or cause denial ...

Oct 13, 2023
CVE-2023-3725
7.6

A buffer overflow vulnerability exists in the Zephyr RTOS CAN bus subsystem, allowing attackers to execute arbitrary code or cause denial of service. ...

Oct 6, 2023
CVE-2023-26076
7.6

This vulnerability allows remote attackers to execute arbitrary code on affected Samsung mobile devices via a crafted 5G network message. It affects S...

Mar 13, 2023
CVE-2021-3555
7.6

A buffer overflow vulnerability in the RTSP server component of Eufy Indoor 2K Indoor Camera allows local attackers to execute arbitrary code remotely...

May 31, 2022
CVE-2021-45524
7.6

This vulnerability allows an authenticated attacker to trigger a buffer overflow on NETGEAR R8000 routers. It affects users with administrative access...

Dec 26, 2021
CVE-2019-25353
7.5

CVE-2019-25353 is a buffer overflow vulnerability in Foscam Video Management System that allows attackers to cause denial of service by sending a spec...

Feb 18, 2026
CVE-2019-25349
7.5

CVE-2019-25349 is a buffer overflow vulnerability in ScadaApp for iOS that allows attackers to cause a denial of service by crashing the application. ...

Feb 18, 2026
CVE-2025-69807
7.5

CVE-2025-69807 is a buffer overflow vulnerability in p2r3 Bareiron that allows unauthenticated remote attackers to send specially crafted packets to c...

Feb 12, 2026
CVE-2020-37213
7.5

CVE-2020-37213 is a buffer overflow vulnerability in TextCrawler Pro that allows attackers to cause denial of service by crashing the application. Att...

Feb 11, 2026
CVE-2020-37209
7.5

CVE-2020-37209 is a buffer overflow vulnerability in SpotFTP 3.0.0.0 that allows attackers to crash the application by entering a 1000-character paylo...

Feb 11, 2026
CVE-2020-37210
7.5

CVE-2020-37210 is a buffer overflow vulnerability in SpotIE 2.9.5 that allows attackers to cause denial of service by crashing the application. Attack...

Feb 11, 2026
CVE-2020-37212
7.5

SpotMSN 2.4.6 contains a buffer overflow vulnerability in the registration name field that allows attackers to crash the application by inputting a 10...

Feb 11, 2026
CVE-2020-37202
7.5

NetworkSleuth 3.0.0.0 contains a buffer overflow vulnerability in the registration key validation that allows attackers to crash the application by su...

Feb 11, 2026
CVE-2020-37204
7.5

RemShutdown 2.9.0.0 contains a buffer overflow vulnerability in its registration key input field that allows attackers to crash the application via de...

Feb 11, 2026
CVE-2020-37205
7.5

CVE-2020-37205 is a buffer overflow vulnerability in RemShutdown 2.9.0.0 that allows attackers to crash the application by sending overly long input t...

Feb 11, 2026
CVE-2020-37207
7.5

CVE-2020-37207 is a buffer overflow vulnerability in SpotDialup's registration key field that allows attackers to crash the application by pasting a 1...

Feb 11, 2026
CVE-2020-37197
7.5

CVE-2020-37197 is a buffer overflow vulnerability in Dnss Domain Name Search Software that allows attackers to cause denial of service by crashing the...

Feb 11, 2026
CVE-2020-37199
7.5

NBMonitor 1.6.6.0 contains a buffer overflow vulnerability in its registration key input field that allows attackers to crash the application by pasti...

Feb 11, 2026
CVE-2020-37191
7.5

CVE-2020-37191 is a buffer overflow vulnerability in Top Password Software Dialup Password Recovery 1.30 that allows attackers to crash the applicatio...

Feb 11, 2026
CVE-2020-37193
7.5

CVE-2020-37193 is a denial of service vulnerability in ZIP Password Recovery 2.30 where attackers can crash the application by providing a specially c...

Feb 11, 2026
CVE-2020-37195
7.5

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration name input field that allows attackers to crash the application via d...

Feb 11, 2026
CVE-2020-37185
7.5

CVE-2020-37185 is a buffer overflow vulnerability in Backup Key Recovery 2.2.5 that allows attackers to crash the application by sending overly long i...

Feb 11, 2026
CVE-2020-37188
7.5

CVE-2020-37188 is a buffer overflow vulnerability in SpotOutlook 1.2.6 that allows attackers to cause denial of service by crashing the application. A...

Feb 11, 2026
CVE-2020-37189
7.5

TaskCanvas 1.4.0 contains a buffer overflow vulnerability in the registration code input field that allows attackers to cause denial of service by cra...

Feb 11, 2026
CVE-2020-37180
7.5

CVE-2020-37180 is a denial of service vulnerability in GTalk Password Finder 2.2.1 where attackers can crash the application by supplying an oversized...

Feb 11, 2026
CVE-2025-69259
7.5

A NULL pointer dereference vulnerability in Trend Micro Apex Central allows remote attackers to cause denial-of-service without authentication. This a...

Jan 8, 2026
CVE-2025-69260
7.5

An out-of-bounds read vulnerability in Trend Micro Apex Central allows remote attackers to cause denial-of-service conditions without authentication. ...

Jan 8, 2026
CVE-2025-50681
7.5

CVE-2025-50681 is a remote denial-of-service vulnerability in igmpproxy versions before commit 2b30c36. Attackers can crash the application by sending...

Dec 19, 2025
CVE-2025-64053
7.5

A buffer overflow vulnerability in Fanvil x210 VoIP phones running firmware 2.12.20 allows attackers to cause denial of service or potentially execute...

Dec 5, 2025
CVE-2025-63679
7.5

A buffer overflow vulnerability in free5gc AMF component allows remote attackers to crash the AMF process by sending a specially crafted UplinkRANConf...

Nov 12, 2025
CVE-2025-60340
7.5

This vulnerability allows attackers to cause denial of service on Tenda AC6 routers by exploiting buffer overflows in the SetClientState function. Att...

Oct 22, 2025
CVE-2025-60343
7.5

This CVE describes multiple buffer overflow vulnerabilities in Tenda AC6 routers that allow attackers to cause denial of service by sending specially ...

Oct 22, 2025
CVE-2025-55603
7.5

A buffer overflow vulnerability exists in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending specially ...

Aug 22, 2025
CVE-2025-55606
7.5

This CVE describes a buffer overflow vulnerability in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sendin...

Aug 22, 2025
CVE-2025-50609
7.5

A buffer overflow vulnerability in Netis WF2880 routers allows attackers to crash the device by sending specially crafted requests to the cgitest.cgi ...

Aug 13, 2025

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,179 CVEs classified as CWE-120, with 360 rated critical and 649 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free