CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,240)
This buffer overflow vulnerability in Zyxel PMG2005-T20B firmware allows unauthenticated attackers to cause denial of service by sending specially cra...
Sep 27, 2023This CVE describes a buffer overflow vulnerability (CWE-120) in Huawei's PMS module that allows denial-of-service attacks. Successful exploitation cau...
Sep 25, 2023A buffer overflow vulnerability in XiongMai NVR firmware allows remote attackers to cause denial of service via crafted requests to the XM component. ...
Sep 11, 2023CVE-2023-42278 is a buffer overflow vulnerability in hutool's JSONUtil.parse() function that could allow attackers to execute arbitrary code or cause ...
Sep 8, 2023A buffer overflow vulnerability in timg v1.5.1 and earlier allows remote attackers to cause denial of service by exploiting memory corruption at a spe...
Sep 1, 2023CVE-2022-46527 is a buffer overflow vulnerability in the NFC data parser of ELSYS ERS 1.5 Sound v2.3.8. This allows attackers to execute arbitrary cod...
Sep 1, 2023A buffer overflow vulnerability in Qdrant v1.3.2 allows remote attackers to cause denial of service by sending specially crafted requests to the chunk...
Aug 29, 2023A buffer overflow vulnerability in O-RAN Software Community's ric-plt-lib-rmr library version 4.9.0 allows remote attackers to cause denial of service...
Aug 28, 2023This vulnerability in Samsung Exynos processors allows attackers to trigger an infinite loop by exploiting improper handling of PPP length parameter i...
Aug 28, 2023This buffer overflow vulnerability in TP-Link wireless routers allows attackers to cause Denial of Service (DoS) by sending specially crafted GET requ...
Aug 21, 2023This vulnerability in Huawei's PMS module allows attackers to exploit improper input validation, potentially causing denial of service by making the h...
Aug 13, 2023This vulnerability in Firefox causes cookie jar inconsistencies when domain cookie limits are exceeded, potentially sending requests with missing cook...
Aug 1, 2023This vulnerability is a buffer overflow in D-LINK DIR-815 router firmware version 1.01, specifically in the /web/captcha.cgi component. Attackers can ...
Jul 18, 2023A buffer overflow vulnerability in TP-Link wireless routers allows attackers to cause Denial of Service (DoS) via crafted GET requests to the /userRpm...
Jun 22, 2023CVE-2023-24584 is a buffer overflow vulnerability in Gallagher Controller 6000's diagnostic web interface upload feature. Attackers can exploit this t...
Jun 1, 2023A buffer overflow vulnerability exists in Qt's SVG rendering component when processing SVG files containing images. This can allow attackers to execut...
May 28, 2023This CVE describes a buffer overflow vulnerability in Huawei video framework caused by addition overflow. Successful exploitation could allow attacker...
May 26, 2023CVE-2021-46885 is a buffer overflow vulnerability in Huawei's video framework caused by addition overflow. Exploitation could allow attackers to overw...
May 26, 2023This CVE describes a buffer overflow vulnerability in Huawei video framework caused by addition overflow. Attackers could exploit this to overwrite me...
May 26, 2023A buffer overflow vulnerability in Zyxel NBG-418N v2 router firmware allows remote unauthenticated attackers to cause denial-of-service conditions by ...
May 1, 2023A buffer overflow vulnerability in the fbwifi_forward.cgi CGI program of affected Zyxel devices allows remote unauthenticated attackers to cause denia...
Apr 24, 2023A buffer overflow vulnerability in Zyxel network devices allows remote unauthenticated attackers to cause denial of service by uploading a crafted con...
Apr 24, 2023APNG_Optimizer v1.4 contains a buffer overflow vulnerability in its processing of ubuntu.png files. This allows attackers to execute arbitrary code or...
Apr 17, 2023A buffer overflow vulnerability in Espruino 2v05.41 allows attackers to trigger denial of service by exploiting the jsvGarbageCollectMarkUsed function...
Apr 4, 2023This CVE describes a heap buffer overflow vulnerability in TensorFlow's TAvgPoolGrad operation. Attackers could exploit this to cause denial of servic...
Mar 25, 2023A buffer overflow vulnerability in Liblouis v3.24.0 allows remote attackers to cause denial of service by exploiting the lou_logFile function. This af...
Mar 16, 2023A buffer overflow vulnerability in Liblouis Lou_Trace v3.24.0 allows remote attackers to cause denial of service by exploiting the resolveSubtable fun...
Mar 16, 2023A buffer overflow vulnerability in PJSIP's DNS resolver allows attackers to execute arbitrary code or cause denial of service by sending specially cra...
Mar 14, 2023This CVE describes a buffer overflow vulnerability in Tenda W15EV1 routers via the picName parameter in the formDelWewifiPi function. Attackers can ex...
Mar 13, 2023This vulnerability allows remote attackers to cause a denial-of-service (DoS) condition on affected BIG-IP systems by sending specially crafted HTTP r...
Feb 1, 2023CVE-2022-32096 is a buffer overflow vulnerability in Rhonabwy's JWE decryption component that allows attackers to cause Denial of Service (DoS) by sen...
Jul 13, 2022This CVE describes a buffer overflow vulnerability in PHP's pdo_mysql extension with mysqlnd driver when connecting with an excessively long password....
Jun 16, 2022A buffer overflow vulnerability in WinAPRS 2.9.0 allows remote attackers to crash the daemon by sending malicious AX.25 packets over VHF radio. This a...
Jun 2, 2022This vulnerability allows remote attackers to execute arbitrary code on Tenda TX9 Pro routers via a buffer overflow in the setIPv6Status() function of...
May 18, 2022This vulnerability affects multiple Siemens SCALANCE industrial network switches. An unauthenticated remote attacker can send specially crafted HTTP r...
Apr 12, 2022CVE-2022-24793 is a buffer overflow vulnerability in PJSIP's DNS resolution component affecting versions 2.12 and prior. It allows attackers to execut...
Apr 6, 2022Two buffer overflow vulnerabilities in the built-in web server of Moxa NPort IAW5000A-I/O Series devices allow remote attackers to cause denial-of-ser...
Apr 1, 2022This is a heap buffer overflow vulnerability in OpenBSD's slaacd daemon, triggered by malicious IPv6 router advertisements containing more than seven ...
Mar 25, 2022CVE-2022-26243 is a buffer overflow vulnerability in Tenda AC10-1200 routers that allows attackers to execute arbitrary code or cause denial of servic...
Mar 23, 2022CVE-2022-24764 is a stack buffer overflow vulnerability in PJSIP multimedia communication library affecting versions 2.12 and prior. It allows attacke...
Mar 22, 2022This CVE describes a buffer overflow vulnerability in Huawei video framework components where input buffer copying occurs without proper size validati...
Mar 10, 2022CVE-2022-21716 is a memory exhaustion vulnerability in Twisted's SSH client and server implementations. Attackers can send unlimited data during SSH v...
Mar 3, 2022CVE-2021-45856 is a buffer overflow vulnerability in the telnet service of Accu-Time Systems MAXIMUS 1.0 time and attendance systems. Attackers can se...
Jan 10, 2022A buffer overflow vulnerability in FTPShell Server v6.83 allows attackers to crash the service via specially crafted requests to the Virtual Path Mapp...
Dec 17, 2021CVE-2021-44429 is a buffer overflow vulnerability in Serva TFTP server that allows remote attackers to crash the daemon via specially crafted TFTP rea...
Nov 29, 2021A buffer overflow vulnerability in Wireshark's Bluetooth SDP dissector allows attackers to cause denial of service via packet injection or specially c...
Nov 19, 2021A buffer overflow vulnerability in the src_parser_trans_stage_1_2_3 function of trgil gilcc allows attackers to cause denial of service by crashing th...
Nov 2, 2021A buffer overflow vulnerability in YotsuyaNight c-http v0.1.0 allows attackers to cause denial of service by sending long URL requests. This affects s...
Nov 2, 2021A buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5 allows attackers to cause denial of service by sending unexpected packets during conn...
Nov 2, 2021This vulnerability in Nsasoft SpotAuditor allows attackers to crash the application by entering 300+ characters in registration fields. It affects use...
Nov 2, 2021About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,240 CVEs classified as CWE-120, with 393 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free