CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,116)
This vulnerability allows remote attackers to execute arbitrary code on Tenda AC7 routers by exploiting a buffer overflow in the timeZone parameter. A...
Mar 19, 2025SoftEther VPN 5.02.5187 contains a buffer overflow vulnerability in PtMakeCert and PtMakeCert2048 functions in Command.c. This allows attackers to exe...
Mar 12, 2025SoftEther VPN 5.02.5187 contains a buffer overflow vulnerability in the UniToStrForSingleChars function within Internat.c. This could allow arbitrary ...
Mar 12, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda i12 routers by sending specially crafted requests to the formSetCfm func...
Feb 20, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda O4 V3.0 routers via a buffer overflow in the SafeSetMacFilter function. ...
Feb 20, 2025This CVE describes a stack overflow vulnerability in Tenda AC8V4 routers that allows remote code execution. Attackers can exploit the shareSpeed param...
Feb 20, 2025CVE-2025-25343 is a critical buffer overflow vulnerability in Tenda AC6 router firmware that allows remote code execution. Attackers can exploit this ...
Feb 12, 2025A buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 allows attackers to crash devices or execute arbitrary commands by exploi...
Feb 11, 2025AutomationDirect C-more EA9 HMI devices contain a buffer overflow vulnerability due to insufficient bounds checking. Attackers can exploit this to cau...
Feb 4, 2025This CVE describes multiple stack buffer overflow vulnerabilities in Qualisys C++ SDK that could allow remote code execution. Attackers could exploit ...
Jan 31, 2025This vulnerability allows remote attackers to execute arbitrary code on RE11S v1.11 devices by exploiting a stack overflow in the pptpUserName paramet...
Jan 16, 2025This vulnerability allows remote attackers to execute arbitrary code on RE11S v1.11 devices via a stack overflow in the PPPoE setup function. Attacker...
Jan 16, 2025H3C N12 V100R005 routers contain a critical buffer overflow vulnerability in the MAC address editing function due to insufficient input validation. At...
Jan 14, 2025H3C N12 V100R005 wireless routers contain a buffer overflow vulnerability in their 2.4G wireless network processing function. Attackers can exploit th...
Jan 14, 2025H3C N12 V100R005 wireless access points contain a critical buffer overflow vulnerability in their web management interface. Attackers can remotely cra...
Jan 14, 2025This CVE describes a stack overflow vulnerability in Tenda AC9 v1.0 routers that allows remote attackers to execute arbitrary code by sending speciall...
Jan 10, 2025A buffer overflow vulnerability in radare2 v5.8.8 allows attackers to execute arbitrary code by manipulating name, type, or group fields. This affects...
Dec 17, 2024This CVE describes a classic buffer overflow vulnerability in RTI Connext Professional components (Core Libraries, Queuing Service, Recording Service,...
Dec 13, 2024CVE-2024-55564 is a buffer overflow vulnerability in the POSIX::2008 Perl package that could allow attackers to execute arbitrary code or cause denial...
Dec 9, 2024A buffer overflow vulnerability in ROS2 Nav2's AMCL process allows remote code execution when processing malicious YAML files. This affects ROS2 Humbl...
Dec 5, 2024A buffer overflow vulnerability in ROS2 Nav2's AMCL process allows remote code execution when processing malicious YAML files. This affects ROS2 Humbl...
Dec 5, 2024A buffer overflow vulnerability in SunBK201 umicat's power() function allows remote attackers to execute arbitrary code by sending specially crafted i...
Nov 29, 2024This vulnerability in MBed OS 6.16.0 allows a buffer overflow when parsing Bluetooth Low Energy (BLE) advertising reports. Attackers could potentially...
Nov 20, 2024A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the 'fromSetS...
Nov 19, 2024This vulnerability in miniupnp library allows buffer overflow due to missing snprintf return value checks, leading to significant data leaks. In Bitco...
Nov 18, 2024This critical vulnerability allows a malicious MMS server to trigger a stack-based buffer overflow in the MZ Automation LibIEC61850 client via special...
Nov 15, 2024SuperScan v4.1 contains a buffer overflow vulnerability in the Hostname/IP parameter that allows attackers to execute arbitrary code. This affects all...
Nov 11, 2024This vulnerability is a buffer overflow in GLib's SOCKS4 proxy implementation due to an off-by-one error. It allows attackers to execute arbitrary cod...
Nov 11, 2024This vulnerability allows remote attackers to execute arbitrary code on Trendnet TEW-820AP routers via stack overflow in the boa HTTP daemon when proc...
Nov 11, 2024CVE-2024-35426 is a critical stack buffer overflow vulnerability in vmir's WebAssembly parser that allows remote code execution. Attackers can exploit...
Nov 8, 2024CVE-2024-46478 is a critical buffer overflow vulnerability in HTMLDOC v1.9.18 that allows remote attackers to execute arbitrary code or cause denial o...
Oct 24, 2024A stack overflow vulnerability in D-Link DIR-820L routers allows remote attackers to execute arbitrary code by sending specially crafted requests to t...
Oct 14, 2024This CVE describes a critical buffer overflow vulnerability in btstack's mesh implementation that allows remote attackers to execute arbitrary code. T...
Sep 18, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK AC1200 T8 routers by exploiting a buffer overflow in the setWizardCfg...
Sep 16, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK AC1200 T8 routers by exploiting a buffer overflow in the setWiFiAclRu...
Sep 16, 2024CVE-2024-41433 is a buffer overflow vulnerability in PingCAP TiDB's expression.ExplainExpressionList component that allows attackers to cause Denial o...
Sep 3, 2024This vulnerability allows attackers to execute arbitrary code or cause denial-of-service on TOTOLINK AC1200 routers by sending specially crafted HTTP ...
Aug 28, 2024This vulnerability allows a malicious RPKI repository to trigger a buffer overflow in FORT validator versions before 1.6.3 by serving a specially craf...
Aug 24, 2024This critical buffer overflow vulnerability in D-Link DIR-860L routers allows attackers to crash devices or execute arbitrary commands remotely. Attac...
Aug 19, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers by exploiting a buffer overflow in the password parame...
Aug 12, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting a buffer overflow in the loginauth funct...
Aug 12, 2024This CVE describes a critical buffer overflow vulnerability in Microchip Technology's Advanced Software Framework DHCP server example code. Attackers ...
Aug 8, 2024This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on Cisco SPA300/500 series IP p...
Aug 7, 2024This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected Cisco IP phones. At...
Aug 7, 2024CVE-2024-41660 is a critical buffer overflow vulnerability in slpd-lite, a unicast SLP UDP server included by default in OpenBMC builds. Attackers can...
Jul 31, 2024This CVE describes a critical vulnerability in AMI BIOS firmware used by certain HP PC products that could allow attackers to execute arbitrary code. ...
Jul 15, 2024A classic buffer overflow vulnerability in the libjansson component of Synology Camera Firmware allows remote attackers to execute arbitrary code on a...
Jun 28, 2024A buffer overflow vulnerability in ASUS RT-AX88U routers allows remote attackers to execute arbitrary code by sending specially crafted cookie data to...
Jun 24, 2024A buffer overflow vulnerability in the Linux kernel's of_modalias() function allows attackers to write beyond allocated memory boundaries. This affect...
Jun 19, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers via a stack overflow in the setWizardCfg function. Att...
Jun 14, 2024About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,116 CVEs classified as CWE-120, with 332 rated critical and 614 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free