CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,240)
This vulnerability in Open5GS allows remote attackers to execute arbitrary code or cause denial of service via a buffer overflow. Attackers can exploi...
Oct 7, 2021CVE-2021-35945 is a buffer overflow vulnerability in Couchbase Server's memcached component that allows remote attackers to crash the service via spec...
Sep 29, 2021A buffer overflow vulnerability in the Xilinx LL TEMAC Ethernet driver in Linux kernel versions before 5.12.13 allows remote attackers to cause denial...
Aug 8, 2021This vulnerability in the prost-types Rust crate allows integer overflow when converting Timestamp to SystemTime, potentially causing crashes or undef...
Aug 8, 2021This CVE describes a buffer overflow vulnerability in lwIP's ICMPv6 packet handling that allows attackers to read sensitive memory contents via crafte...
Jul 22, 2021A buffer overflow vulnerability in QuickJS's quickjs.c allows remote attackers to cause denial of service by crashing the application. This affects sy...
Jul 13, 2021A buffer overflow vulnerability in the jsG_markobject function of mujs JavaScript interpreter allows remote attackers to cause denial of service. This...
Jul 13, 2021A buffer overflow vulnerability in Qualcomm Snapdragon chipsets due to insufficient length validation in BA requests. This allows attackers to execute...
Jul 13, 2021CVE-2021-33185 is a buffer overflow vulnerability in SerenityOS's TestBitmap component that could allow attackers to read sensitive information from m...
Jun 18, 2021CVE-2021-31661 is a buffer overflow vulnerability in RIOT-OS that could allow attackers to read beyond allocated memory boundaries, potentially exposi...
Jun 18, 2021This buffer overflow vulnerability in RIOT-OS allows attackers to read beyond allocated memory boundaries, potentially exposing sensitive information ...
Jun 18, 2021A buffer overflow vulnerability in Libsixel's sixel_encoder_encode_bytes function allows attackers to cause denial of service by sending specially cra...
Apr 14, 2021A buffer overflow vulnerability in TP-Link WR2041 v1 router firmware allows remote attackers to crash the router by sending a specially crafted HTTP r...
Apr 14, 2021This vulnerability in ClamAV's email parsing module allows an unauthenticated remote attacker to cause a denial of service by sending a crafted email,...
Apr 8, 2021CVE-2020-16146 is a buffer overflow vulnerability in Espressif ESP-IDF's BluFi provisioning component. Attackers can exploit this by sending crafted W...
Jan 12, 2021CVE-2020-29596 is a buffer overflow vulnerability in MiniWeb HTTP server 0.8.19 that allows remote attackers to crash the server via a specially craft...
Dec 21, 2020CVE-2020-6085 is a denial-of-service vulnerability in Allen-Bradley Flex IO devices where a specially crafted ENIP request with a malformed Electronic...
Oct 19, 2020CVE-2020-6086 is a denial-of-service vulnerability in Allen-Bradley Flex IO 1794-AENT/B devices where a specially crafted ENIP request causes the devi...
Oct 14, 2020A buffer overflow vulnerability in SonicOS allows remote unauthenticated attackers to cause denial of service by crashing the firewall. This affects S...
Oct 12, 2020A buffer overflow vulnerability in SonicOS SSLVPN service allows remote unauthenticated attackers to crash the firewall via denial of service. This af...
Oct 12, 2020CVE-2020-15956 is a buffer overflow vulnerability in ACTi NVR3 Standard Server that allows remote unauthenticated attackers to crash the application v...
Aug 4, 2020This vulnerability in rejetto HFS (HTTP File Server) allows remote attackers to trigger a buffer overflow via concurrent HTTP requests with long URIs ...
Jun 8, 2020An unauthenticated attacker on the same network segment can send specially crafted OSPFv2 packets to vulnerable Cisco IOS XE devices, causing them to ...
Apr 24, 2024A buffer overflow vulnerability exists in the password recovery feature of Hikvision NVR/DVR devices. Attackers on the same local network can send spe...
Nov 23, 2023This CVE describes a buffer overflow vulnerability in TOTOLINK A800R routers through the downloadFile.cgi endpoint's v25 parameter. Attackers can expl...
Apr 23, 2025This CVE describes a buffer overflow vulnerability in TOTOLINK A810R routers through the downloadFile.cgi endpoint's v25 parameter. Attackers can expl...
Apr 23, 2025A buffer overflow vulnerability in TOTOLINK routers' downloadFile.cgi component allows attackers to execute arbitrary code by sending specially crafte...
Apr 23, 2025This CVE describes a buffer overflow vulnerability in TOTOLINK A800R routers through the downloadFile.cgi endpoint's v14 parameter. Attackers can expl...
Apr 23, 2025A buffer overflow vulnerability in Linksys WAP610N wireless access points allows remote attackers to execute arbitrary code by exploiting improper inp...
Feb 11, 2025CVE-2024-41176 is a buffer overflow vulnerability in the MPD package of TwinCAT/BSD that allows authenticated local attackers with low privileges to c...
Aug 27, 2024A buffer overflow vulnerability in RTI Connext Professional's XML parsing allows attackers to execute arbitrary code, leak sensitive information, or c...
May 21, 2024This vulnerability allows memory corruption when processing audio files with large input buffers, potentially leading to arbitrary code execution. It ...
May 6, 2024This vulnerability allows memory corruption when parsing QCP audio files with invalid chunk data sizes. Attackers could potentially execute arbitrary ...
Mar 4, 2024CVE-2023-6881 is a buffer overflow vulnerability in the is_mount_point function in Zephyr RTOS. This vulnerability could allow attackers to execute ar...
Feb 29, 2024This vulnerability allows memory corruption in video processing when parsing Videoinfo atoms with sizes larger than expected. Attackers could potentia...
Feb 6, 2024A buffer overflow vulnerability in Frhed hex editor version 1.6.0 allows attackers to execute arbitrary code by exploiting a long filename argument th...
Nov 27, 2023This vulnerability in the node-bluetooth-serial-port package allows attackers to cause a buffer overflow by providing overly long input to the findSer...
Mar 9, 2023This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers and extenders. Successful exploitation co...
Dec 26, 2021This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers. Successful exploitation could lead to re...
Dec 26, 2021This buffer overflow vulnerability in Samsung Notes' libSPenBase library allows attackers to execute arbitrary code on affected devices. It affects Sa...
Oct 6, 2021CVE-2021-1909 is a buffer overflow vulnerability in Qualcomm Snapdragon trusted applications due to insufficient parameter length validation. This all...
Sep 9, 2021A buffer overflow vulnerability in Siemens LOGO! programmable logic controllers allows attackers to execute arbitrary code by sending specially crafte...
Nov 11, 2025This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows remote attackers with administrator access to execute arbitra...
Nov 22, 2024This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows remote attackers with administrator access to execute arbitra...
Nov 22, 2024This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows attackers to execute arbitrary code remotely. It affects mult...
May 21, 2024A critical buffer overflow vulnerability in Totolink X2000R routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...
Jan 9, 2024This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WR840N routers via a buffer overflow in the password reset feature....
Apr 18, 2022This CVE describes a buffer overflow vulnerability in TP-LINK TL-WR840N routers via the DNSServers parameter. Attackers can exploit this to execute ar...
Mar 28, 2022This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR840N routers via a buffer overflow in the httpRemotePort paramete...
Mar 28, 2022Multiple buffer overflow vulnerabilities in HPE iLO Amplifier Pack allow highly privileged users to remotely execute arbitrary code. This affects all ...
Feb 24, 2022About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,240 CVEs classified as CWE-120, with 393 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free