CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,240)
A buffer overflow vulnerability in the Draytek Vigor 3910 router's v2x00.cgi component allows attackers to cause Denial of Service (DoS) by sending sp...
Sep 18, 2024This vulnerability allows attackers to trigger a buffer overflow in Draytek Vigor 3910 routers by sending crafted input to the sSrvAddr parameter in v...
Sep 18, 2024A buffer overflow vulnerability exists in the AControlIp1 parameter of the acontrol.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Atta...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to ...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the CGIbyF...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sStRtM...
Sep 18, 2024A buffer overflow vulnerability exists in the profname parameter of the v2x00.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Attackers ...
Sep 18, 2024A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sInRCS...
Sep 18, 2024YugabyteDB v2.21.1.0 contains a buffer overflow vulnerability in the 'insert into' parameter that could allow attackers to execute arbitrary code or c...
Sep 3, 2024A buffer overflow vulnerability in the libclinkc library of Zyxel VMG8825-T50K firmware allows unauthenticated attackers to cause denial of service by...
Sep 3, 2024A buffer overflow vulnerability in Accutech Manager allows attackers to crash the service by sending specially crafted requests to port 2536/TCP. This...
Aug 20, 2024A buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code via the Virtual_Data_Check function in the htt...
Jul 29, 2024A buffer overflow vulnerability in NEUQ_board v1.0 allows remote attackers to cause denial of service by exploiting the password.h component. This aff...
Jul 29, 2024This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...
Jul 9, 2024A buffer overflow vulnerability in Renesas arm-trusted-firmware allows local attackers to execute arbitrary code by manipulating memory writes. This a...
Jul 8, 2024A buffer overflow vulnerability in SILA Embedded Solutions GmbH's freemodbus library (v.2018-09-12) allows remote attackers to cause denial of service...
Jul 8, 2024A stack buffer overflow vulnerability in zziplib version 0.13.77 allows attackers to cause denial of service by exploiting the __zzip_fetch_disk_trail...
Jun 27, 2024A buffer overflow vulnerability in PX4-Autopilot v1.14.3 allows attackers to execute arbitrary code or crash the system by exploiting the topic_name p...
Jun 25, 2024This buffer overflow vulnerability in TOTOLINK AC1200 router firmware allows attackers to send specially crafted HTTP or MQTT requests to the 'setNoti...
Jun 11, 2024FlyFish v3.0.0 contains a buffer overflow vulnerability in the password parameter on the login page. Attackers can exploit this to cause Denial of Ser...
May 16, 2024A buffer overflow vulnerability in Phoenix SecureCore UEFI firmware's variable handling allows attackers to execute arbitrary code with high privilege...
May 14, 2024A buffer overflow vulnerability in libmodbus v3.1.10 allows attackers to cause crashes or potentially execute arbitrary code by sending specially craf...
May 8, 2024A buffer overflow vulnerability in msoulier's tftpy library allows remote attackers to cause denial of service by sending specially crafted packets to...
Apr 29, 2024A buffer overflow vulnerability in GoBGP's handlingError function allows remote attackers to cause denial of service by sending specially crafted pack...
Apr 29, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1206 routers by exploiting a stack-based buffer overflow in the RouteS...
Apr 23, 2024A buffer overflow vulnerability in Tenda AC500 routers allows remote attackers to cause denial of service by sending specially crafted requests to the...
Apr 17, 2024CVE-2024-23077 is a disputed vulnerability in JFreeChart v1.5.4 where an ArrayIndexOutOfBounds exception could potentially be triggered in the Compass...
Apr 10, 2024This CVE describes a data verification error vulnerability in a kernel module that could allow attackers to bypass security checks. Successful exploit...
Apr 8, 2024This vulnerability allows attackers to cause a Denial of Service (DoS) on LBT T300-T390 routers by sending a specially crafted POST request that trigg...
Mar 1, 2024This critical vulnerability in D-Link DIR-600M C1 routers allows remote attackers to execute arbitrary code via a buffer overflow in the Telnet servic...
Feb 23, 2024This vulnerability in the cbor2 Python library allows attackers to cause denial-of-service by sending specially crafted CBOR objects that trigger exce...
Feb 19, 2024A buffer overflow vulnerability in the nomath() function of Mathtex v1.05 and earlier allows remote attackers to cause denial of service by sending a ...
Jan 24, 2024A buffer overflow vulnerability in Tenda i29 routers allows remote attackers to cause denial of service by sending specially crafted requests to the p...
Jan 5, 2024This vulnerability in Stormshield Network Security (SNS) firewalls allows attackers to overflow the cookie threshold, preventing IPsec connections fro...
Dec 25, 2023Asterisk contains a buffer overflow vulnerability in the PJSIP_HEADER dialplan function's 'update' functionality. This can cause memory corruption or ...
Dec 14, 2023This CVE describes a buffer overflow vulnerability in multiple Siemens industrial automation products. An attacker can send specially crafted requests...
Dec 12, 2023This CVE describes a buffer overflow vulnerability in Zumtobel Netlink CCD Onboard firmware that allows attackers to execute arbitrary code or cause d...
Nov 29, 2023A buffer overflow vulnerability in free5gc 3.3.0 allows attackers to cause denial of service by sending specially crafted PFCP messages with manipulat...
Nov 15, 2023A buffer overflow vulnerability in free5gc's UPF and SMF components allows attackers to cause denial of service by sending specially crafted PFCP mess...
Nov 13, 2023This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a buffer overflow in Memcached proxy mode. Attacke...
Oct 27, 2023A buffer overflow vulnerability in COVESA's dlt-daemon up to version 2.18.8 allows attackers to execute arbitrary code or cause denial of service by s...
Oct 17, 2023This vulnerability in Netis N3Mv2 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted input to the servDomain par...
Oct 13, 2023This CVE describes a command injection vulnerability in Xiaomi routers that allows attackers to execute arbitrary commands on the device. Attackers ca...
Oct 11, 2023This CVE describes a buffer overflow vulnerability in Mbed TLS versions 2.x before 2.28.5 and 3.x before 3.5.0. Attackers could exploit this to execut...
Oct 7, 2023This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow by sending specially crafted input to the TXPower paramete...
Oct 5, 2023This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow via the CurrentPassword parameter, potentially causing a D...
Oct 5, 2023A buffer overflow vulnerability in D-Link DIR-823G routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the EndTime p...
Oct 5, 2023This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow by sending specially crafted input to the MacAddress param...
Oct 5, 2023This vulnerability in D-Link DIR-823G routers allows attackers to trigger a buffer overflow via the StartTime parameter in the SetParentsControlInfo f...
Oct 5, 2023A buffer overflow vulnerability in D-Link DIR-823G routers allows attackers to cause Denial of Service (DoS) by sending specially crafted SSID input t...
Oct 5, 2023About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,240 CVEs classified as CWE-120, with 393 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free