CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,240
Total CVEs
393
Critical
677
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 94
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 48
6 Debian 40
7 Netgear 37
8 Linux 35
9 Fedoraproject 32
10 Google 22

All Buffer Copy without Size Check CVEs (1,240)

CVE-2024-46580
7.5

A buffer overflow vulnerability in the Draytek Vigor 3910 router's v2x00.cgi component allows attackers to cause Denial of Service (DoS) by sending sp...

Sep 18, 2024
CVE-2024-46582
7.5

This vulnerability allows attackers to trigger a buffer overflow in Draytek Vigor 3910 routers by sending crafted input to the sSrvAddr parameter in v...

Sep 18, 2024
CVE-2024-46584
7.5

A buffer overflow vulnerability exists in the AControlIp1 parameter of the acontrol.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Atta...

Sep 18, 2024
CVE-2024-46586
7.5

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to ...

Sep 18, 2024
CVE-2024-46550
7.5

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the CGIbyF...

Sep 18, 2024
CVE-2024-46552
7.5

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sStRtM...

Sep 18, 2024
CVE-2024-46554
7.5

A buffer overflow vulnerability exists in the profname parameter of the v2x00.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Attackers ...

Sep 18, 2024
CVE-2024-46556
7.5

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sInRCS...

Sep 18, 2024
CVE-2024-41435
7.5

YugabyteDB v2.21.1.0 contains a buffer overflow vulnerability in the 'insert into' parameter that could allow attackers to execute arbitrary code or c...

Sep 3, 2024
CVE-2024-5412
7.5

A buffer overflow vulnerability in the libclinkc library of Zyxel VMG8825-T50K firmware allows unauthenticated attackers to cause denial of service by...

Sep 3, 2024
CVE-2024-6918
7.5

A buffer overflow vulnerability in Accutech Manager allows attackers to crash the service by sending specially crafted requests to port 2536/TCP. This...

Aug 20, 2024
CVE-2024-33365
7.5

A buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code via the Virtual_Data_Check function in the htt...

Jul 29, 2024
CVE-2024-41631
7.5

A buffer overflow vulnerability in NEUQ_board v1.0 allows remote attackers to cause denial of service by exploiting the password.h component. This aff...

Jul 29, 2024
CVE-2024-6604
7.5

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Jul 9, 2024
CVE-2024-6563
7.5

A buffer overflow vulnerability in Renesas arm-trusted-firmware allows local attackers to execute arbitrary code by manipulating memory writes. This a...

Jul 8, 2024
CVE-2024-31504
7.5

A buffer overflow vulnerability in SILA Embedded Solutions GmbH's freemodbus library (v.2018-09-12) allows remote attackers to cause denial of service...

Jul 8, 2024
CVE-2024-39134
7.5

A stack buffer overflow vulnerability in zziplib version 0.13.77 allows attackers to cause denial of service by exploiting the __zzip_fetch_disk_trail...

Jun 27, 2024
CVE-2024-38952
7.5

A buffer overflow vulnerability in PX4-Autopilot v1.14.3 allows attackers to execute arbitrary code or crash the system by exploiting the topic_name p...

Jun 25, 2024
CVE-2024-36650
7.5

This buffer overflow vulnerability in TOTOLINK AC1200 router firmware allows attackers to send specially crafted HTTP or MQTT requests to the 'setNoti...

Jun 11, 2024
CVE-2024-34905
7.5

FlyFish v3.0.0 contains a buffer overflow vulnerability in the password parameter on the login page. Attackers can exploit this to cause Denial of Ser...

May 16, 2024
CVE-2024-0762
7.5

A buffer overflow vulnerability in Phoenix SecureCore UEFI firmware's variable handling allows attackers to execute arbitrary code with high privilege...

May 14, 2024
CVE-2024-34244
7.5

A buffer overflow vulnerability in libmodbus v3.1.10 allows attackers to cause crashes or potentially execute arbitrary code by sending specially craf...

May 8, 2024
CVE-2023-46566
7.5

A buffer overflow vulnerability in msoulier's tftpy library allows remote attackers to cause denial of service by sending specially crafted packets to...

Apr 29, 2024
CVE-2023-46565
7.5

A buffer overflow vulnerability in GoBGP's handlingError function allows remote attackers to cause denial of service by sending specially crafted pack...

Apr 29, 2024
CVE-2024-33214
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1206 routers by exploiting a stack-based buffer overflow in the RouteS...

Apr 23, 2024
CVE-2023-46060
7.5

A buffer overflow vulnerability in Tenda AC500 routers allows remote attackers to cause denial of service by sending specially crafted requests to the...

Apr 17, 2024
CVE-2024-23077
7.5

CVE-2024-23077 is a disputed vulnerability in JFreeChart v1.5.4 where an ArrayIndexOutOfBounds exception could potentially be triggered in the Compass...

Apr 10, 2024
CVE-2023-52549
7.5

This CVE describes a data verification error vulnerability in a kernel module that could allow attackers to bypass security checks. Successful exploit...

Apr 8, 2024
CVE-2024-27572
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) on LBT T300-T390 routers by sending a specially crafted POST request that trigg...

Mar 1, 2024
CVE-2024-1786
7.5

This critical vulnerability in D-Link DIR-600M C1 routers allows remote attackers to execute arbitrary code via a buffer overflow in the Telnet servic...

Feb 23, 2024
CVE-2024-26134
7.5

This vulnerability in the cbor2 Python library allows attackers to cause denial-of-service by sending specially crafted CBOR objects that trigger exce...

Feb 19, 2024
CVE-2023-51888
7.5

A buffer overflow vulnerability in the nomath() function of Mathtex v1.05 and earlier allows remote attackers to cause denial of service by sending a ...

Jan 24, 2024
CVE-2023-50991
7.5

A buffer overflow vulnerability in Tenda i29 routers allows remote attackers to cause denial of service by sending specially crafted requests to the p...

Jan 5, 2024
CVE-2023-47091
7.5

This vulnerability in Stormshield Network Security (SNS) firewalls allows attackers to overflow the cookie threshold, preventing IPsec connections fro...

Dec 25, 2023
CVE-2023-37457
7.5

Asterisk contains a buffer overflow vulnerability in the PJSIP_HEADER dialplan function's 'update' functionality. This can cause memory corruption or ...

Dec 14, 2023
CVE-2023-46283
7.5

This CVE describes a buffer overflow vulnerability in multiple Siemens industrial automation products. An attacker can send specially crafted requests...

Dec 12, 2023
CVE-2023-24294
7.5

This CVE describes a buffer overflow vulnerability in Zumtobel Netlink CCD Onboard firmware that allows attackers to execute arbitrary code or cause d...

Nov 29, 2023
CVE-2023-47347
7.5

A buffer overflow vulnerability in free5gc 3.3.0 allows attackers to cause denial of service by sending specially crafted PFCP messages with manipulat...

Nov 15, 2023
CVE-2023-47346
7.5

A buffer overflow vulnerability in free5gc's UPF and SMF components allows attackers to cause denial of service by sending specially crafted PFCP mess...

Nov 13, 2023
CVE-2023-46852
7.5

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a buffer overflow in Memcached proxy mode. Attacke...

Oct 27, 2023
CVE-2023-36321
7.5

A buffer overflow vulnerability in COVESA's dlt-daemon up to version 2.18.8 allows attackers to execute arbitrary code or cause denial of service by s...

Oct 17, 2023
CVE-2023-45464
7.5

This vulnerability in Netis N3Mv2 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted input to the servDomain par...

Oct 13, 2023
CVE-2023-26320
7.5

This CVE describes a command injection vulnerability in Xiaomi routers that allows attackers to execute arbitrary commands on the device. Attackers ca...

Oct 11, 2023
CVE-2023-43615
7.5

This CVE describes a buffer overflow vulnerability in Mbed TLS versions 2.x before 2.28.5 and 3.x before 3.5.0. Attackers could exploit this to execut...

Oct 7, 2023
CVE-2023-44838
7.5

This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow by sending specially crafted input to the TXPower paramete...

Oct 5, 2023
CVE-2023-44828
7.5

This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow via the CurrentPassword parameter, potentially causing a D...

Oct 5, 2023
CVE-2023-44830
7.5

A buffer overflow vulnerability in D-Link DIR-823G routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the EndTime p...

Oct 5, 2023
CVE-2023-44832
7.5

This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow by sending specially crafted input to the MacAddress param...

Oct 5, 2023
CVE-2023-44834
7.5

This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow via the StartTime parameter in the SetParentsControlInfo f...

Oct 5, 2023
CVE-2023-44836
7.5

A buffer overflow vulnerability in D-Link DIR-823G routers allows attackers to cause Denial of Service (DoS) by sending specially crafted SSID input t...

Oct 5, 2023

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,240 CVEs classified as CWE-120, with 393 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free