CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,240)
CVE-2025-50681 is a remote denial-of-service vulnerability in igmpproxy versions before commit 2b30c36. Attackers can crash the application by sending...
Dec 19, 2025A buffer overflow vulnerability in Fanvil x210 VoIP phones running firmware 2.12.20 allows attackers to cause denial of service or potentially execute...
Dec 5, 2025A buffer overflow vulnerability in free5gc AMF component allows remote attackers to crash the AMF process by sending a specially crafted UplinkRANConf...
Nov 12, 2025This vulnerability allows attackers to cause denial of service on Tenda AC6 routers by exploiting buffer overflows in the SetClientState function. Att...
Oct 22, 2025This CVE describes multiple buffer overflow vulnerabilities in Tenda AC6 routers that allow attackers to cause denial of service by sending specially ...
Oct 22, 2025A buffer overflow vulnerability exists in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending specially ...
Aug 22, 2025This CVE describes a buffer overflow vulnerability in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sendin...
Aug 22, 2025A buffer overflow vulnerability in Netis WF2880 routers allows attackers to crash the device by sending specially crafted requests to the cgitest.cgi ...
Aug 13, 2025A buffer overflow vulnerability in Netis WF2880 routers allows attackers to cause denial of service by sending specially crafted payloads to the cgite...
Aug 13, 2025A buffer overflow vulnerability in Netis WF2880 routers allows attackers to crash the device by sending specially crafted payloads to the cgitest.cgi ...
Aug 13, 2025A heap buffer overflow vulnerability in gdk-pixbuf and glib allows processing malicious JPEG images to cause out-of-bounds memory reads. This can lead...
Jul 8, 2025This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or crash the device by sending specially crafted re...
Jul 3, 2025A buffer overflow vulnerability exists in the upload.cgi component of WS-WN572HP3 devices, allowing attackers to cause Denial of Service through speci...
May 14, 2025This vulnerability allows remote attackers to crash the web server on Tenda W6_S routers by sending a specially crafted POST request with a malicious ...
Mar 28, 2025A buffer overflow vulnerability in Telesquare TLR-2005KSH routers allows remote attackers to read sensitive information from memory via the systemutil...
Mar 26, 2025Tenda RX3 routers running vulnerable firmware are susceptible to a buffer overflow attack via the schedStartTime and schedEndTime parameters in the /g...
Mar 13, 2025Tenda RX3 routers running specific firmware versions contain a buffer overflow vulnerability in the deviceId parameter of the saveParentControlInfo en...
Mar 13, 2025Tenda RX3 routers running specific firmware versions contain a buffer overflow vulnerability in the time configuration function. Attackers can send sp...
Mar 13, 2025A buffer overflow vulnerability in Tenda RX3 routers allows attackers to cause denial of service via specially crafted packets sent to the /goform/Set...
Mar 13, 2025This buffer overflow vulnerability in Tenda RX3 routers allows attackers to cause denial of service by sending specially crafted packets to the web in...
Mar 13, 2025This vulnerability in Qualcomm components allows a denial-of-service attack when processing country information elements. It affects devices using Qua...
Mar 3, 2025A buffer overflow vulnerability in ProFTPD allows remote attackers to execute arbitrary code or cause denial of service by sending a maliciously craft...
Feb 6, 2025This vulnerability in BIG-IP APM allows an attacker to send specially crafted requests that cause the Traffic Management Microkernel (TMM) to terminat...
Feb 5, 2025A heap buffer overflow vulnerability in the XML Text Escaping component of Qualisys C++ SDK allows attackers to cause Denial of Service (DoS) by sendi...
Jan 31, 2025This is a buffer overflow vulnerability in Silicon Labs Gecko OS that allows network-adjacent attackers to execute arbitrary code without authenticati...
Jan 31, 2025A heap buffer overflow vulnerability in SharkSSL's server-side handshake implementation allows remote attackers to cause denial-of-service by sending ...
Jan 23, 2025A buffer overflow vulnerability in Magma's decode_access_point_name_ie function allows attackers to cause denial of service via crafted NAS packets. T...
Jan 21, 2025This vulnerability is a buffer overflow in the decode_pdn_address function of the Linux Foundation Magma software, affecting versions up to 1.8.0. It ...
Jan 21, 2025A buffer overflow vulnerability in Magma's decode_traffic_flow_template_packet_filter function allows attackers to cause denial of service via crafted...
Jan 21, 2025A stack overflow vulnerability in OpenAirInterface's 5G AMF component allows attackers to cause denial of service by repeatedly establishing SCTP conn...
Jan 21, 2025A buffer overflow vulnerability in Elspec Engineering G5 Digital Fault Recorder firmware allows attackers to execute arbitrary code or cause denial of...
Jan 7, 2025CVE-2024-52949 is a stack-based buffer overflow vulnerability in iptraf-ng 1.2.1 that allows attackers to execute arbitrary code or cause denial of se...
Dec 16, 2024A buffer overflow vulnerability in the libclinkc library used by Zyxel VMG8825-T50K devices allows attackers to cause temporary denial of service agai...
Dec 3, 2024This vulnerability in MBed OS 6.16.0 allows attackers to execute arbitrary write operations via specially crafted HCI packets, leading to potential re...
Nov 20, 2024This vulnerability in MBed OS 6.16.0 allows attackers to trigger a buffer overflow during HCI packet processing, leading to arbitrary memory writes. A...
Nov 20, 2024A buffer overflow vulnerability in Driver Booster v10.6 allows attackers to execute arbitrary code by exploiting the Host parameter in the Customize p...
Nov 11, 2024This vulnerability allows remote attackers to cause denial of service in GStreamer RTSP server by sending specially crafted hexstream requests. The in...
Oct 22, 2024This vulnerability in Oracle WebLogic Server allows unauthenticated attackers to cause denial of service by crashing or hanging the server via HTTP re...
Oct 15, 2024This vulnerability in Django's urlize() and urlizetrunc() template filters allows attackers to cause denial-of-service by submitting very large inputs...
Oct 8, 2024Triangle Microworks IEC 61850 Client libraries before version 12.2.0 have a buffer overflow vulnerability due to missing size checks when processing m...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sIpv6A...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to ...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the trapco...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the saveit...
Sep 18, 2024CVE-2024-46597 is a buffer overflow vulnerability in Draytek Vigor 3910 routers affecting the sPubKey parameter in dialin.cgi. Attackers can exploit t...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the newPro...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to ...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sProfi...
Sep 18, 2024A buffer overflow vulnerability exists in the sAppName parameter of the sslapp.cgi component in Draytek Vigor 3910 firmware v4.3.2.6. Attackers can ex...
Sep 18, 2024This vulnerability allows attackers to cause a Denial of Service (DoS) on Draytek Vigor 3910 routers by exploiting a buffer overflow in the sPeerId pa...
Sep 18, 2024About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,240 CVEs classified as CWE-120, with 393 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free