CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,245
Total CVEs
398
Critical
677
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 96
2 Tenda 59
3 Dlink 52
4 Totolink 52
5 Apple 48
6 Debian 40
7 Netgear 37
8 Linux 35
9 Fedoraproject 32
10 Google 22

All Buffer Copy without Size Check CVEs (1,245)

CVE-2023-7222
7.2

A critical buffer overflow vulnerability in Totolink X2000R routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...

Jan 9, 2024
CVE-2021-46122
7.2

This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WR840N routers via a buffer overflow in the password reset feature....

Apr 18, 2022
CVE-2022-26639
7.2

This CVE describes a buffer overflow vulnerability in TP-LINK TL-WR840N routers via the DNSServers parameter. Attackers can exploit this to execute ar...

Mar 28, 2022
CVE-2022-26641
7.2

This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR840N routers via a buffer overflow in the httpRemotePort paramete...

Mar 28, 2022
CVE-2021-29220
7.2

Multiple buffer overflow vulnerabilities in HPE iLO Amplifier Pack allow highly privileged users to remotely execute arbitrary code. This affects all ...

Feb 24, 2022
CVE-2021-22934
7.2

This vulnerability allows an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buff...

Aug 16, 2021
CVE-2021-22982
7.2

This vulnerability is a buffer overflow in the big3d daemon on F5 BIG-IP DNS and GTM systems. It allows remote attackers to potentially execute arbitr...

Feb 12, 2021
CVE-2025-55131
7.1

A Node.js vulnerability in the vm module's buffer allocation can expose uninitialized memory when timeouts interrupt allocations. This may leak sensit...

Jan 20, 2026
CVE-2025-44951
7.1

A buffer overflow vulnerability in the PFCP library of open5gs allows a local attacker to execute arbitrary code or cause denial of service by providi...

Jun 18, 2025
CVE-2025-28395
7.1

A buffer overflow vulnerability exists in D-LINK DI-8100 routers in the ipsec_road_asp function via the host_ip parameter. This allows attackers to po...

Apr 1, 2025
CVE-2024-52065
7.1

A buffer overflow vulnerability in RTI Connext Professional's Persistence Service on non-Windows systems allows attackers to execute arbitrary code or...

Dec 13, 2024
CVE-2024-4640
7.1

OnCell G3470A-LTE Series devices with firmware v1.7.7 and earlier have a buffer overflow vulnerability due to missing bounds checking. An attacker cou...

Jun 25, 2024
CVE-2023-41112
7.1

A buffer overflow vulnerability in Samsung Exynos processors allows attackers to cause abnormal termination (crash) of mobile devices by sending speci...

Nov 8, 2023
CVE-2023-4264
7.1

CVE-2023-4264 is a buffer overflow vulnerability in the Zephyr RTOS Bluetooth subsystem that could allow attackers to execute arbitrary code or cause ...

Sep 27, 2023
CVE-2023-4259
7.1

Two buffer overflow vulnerabilities in the Zephyr eS-WiFi driver allow attackers to execute arbitrary code or cause denial of service by sending speci...

Sep 26, 2023
CVE-2023-20168
7.1

An unauthenticated local attacker can cause Cisco NX-OS devices to crash and reload by entering a crafted string at the login prompt when TACACS+ or R...

Aug 23, 2023
CVE-2022-24788
7.1

CVE-2022-24788 is a buffer overrun vulnerability in Vyper smart contract language where importing functions from JSON interfaces that return bytes gen...

Apr 13, 2022
CVE-2021-42716
7.1

A buffer overflow vulnerability in stb_image.h's PNM loader incorrectly interprets 16-bit PGM files as 8-bit, causing memory corruption when convertin...

Oct 21, 2021
CVE-2025-5222
7.0

A stack buffer overflow vulnerability in International Components for Unicode (ICU) allows local attackers to execute arbitrary code through the genrb...

May 27, 2025
CVE-2025-24209
7.0

This CVE describes a buffer overflow vulnerability in Apple's web content processing components. Attackers can cause unexpected process crashes by tri...

Mar 31, 2025
CVE-2024-22905
7.0

A buffer overflow vulnerability in ARM mbed-os v6.17.0 allows remote attackers to execute arbitrary code via crafted scripts targeting the hciTrSerial...

Apr 19, 2024
CVE-2024-25115
7.0

This vulnerability in RedisBloom allows authenticated users to execute specially crafted CF.LOADCHUNK commands to trigger a heap overflow, potentially...

Apr 9, 2024
CVE-2024-2452
7.0

This vulnerability in Eclipse ThreadX NetX Duo allows an attacker to cause an integer wrap-around in the __portable_aligned_alloc() function, leading ...

Mar 26, 2024
CVE-2023-5184
7.0

This CVE involves two signed-to-unsigned conversion errors and buffer overflow vulnerabilities in Zephyr RTOS IPM drivers. Successful exploitation cou...

Sep 27, 2023
CVE-2023-2597
7.0

This is a buffer overflow vulnerability in Eclipse OpenJ9's shared cache feature, which is enabled by default. Attackers could exploit this to cause d...

May 22, 2023
CVE-2025-54632
6.8

This CVE describes a buffer overflow vulnerability in Huawei's HVB module due to insufficient data length verification. Attackers could exploit this t...

Aug 6, 2025
CVE-2024-44866
6.8

A buffer overflow vulnerability in MuseScore Studio's GuitarPro file parser allows attackers to execute arbitrary code or crash the application by ope...

Mar 17, 2025
CVE-2024-56456
6.8

This vulnerability allows attackers to crash systems by sending malformed glTF 3D model files to unpatched software. It affects any application using ...

Jan 8, 2025
CVE-2024-25076
6.8

This vulnerability allows attackers to execute arbitrary code on Renesas SmartBond DA1469x devices by exploiting a buffer overflow in the bootrom's Fl...

Jul 10, 2024
CVE-2025-47334
6.7

This vulnerability involves memory corruption in Qualcomm camera drivers when processing shared command buffer packets between userspace and kernel. I...

Jan 7, 2026
CVE-2025-47335
6.7

This CVE describes a memory corruption vulnerability in Qualcomm hardware clock configuration parsing. Attackers could potentially execute arbitrary c...

Jan 7, 2026
CVE-2024-49829
6.7

This vulnerability allows memory corruption during context user dumps due to insufficient buffer length validation. Attackers could potentially execut...

May 6, 2025
CVE-2025-24153
6.7

A buffer overflow vulnerability in macOS allows applications with root privileges to execute arbitrary code with kernel privileges. This could lead to...

Jan 27, 2025
CVE-2017-13308
6.7

CVE-2017-13308 is a buffer overflow vulnerability in MediaTek thermal sensor drivers that allows local privilege escalation. Attackers can exploit imp...

Dec 5, 2024
CVE-2024-33030
6.7

This CVE describes a memory corruption vulnerability in Qualcomm's IPC frequency table parameter parsing for LPLH (likely Low Power Low Hardware). Whe...

Nov 4, 2024
CVE-2024-3506
6.7

A buffer overflow vulnerability in specific camera drivers within XProtect Device Pack allows attackers with internal network access to execute arbitr...

Oct 8, 2024
CVE-2024-23375
6.7

This CVE describes a memory corruption vulnerability in Qualcomm network scanning functionality that could allow an attacker to execute arbitrary code...

Oct 7, 2024
CVE-2024-23378
6.7

This vulnerability allows memory corruption through IOCTL calls to the MSM module during audio operations on Qualcomm devices. Attackers could potenti...

Oct 7, 2024
CVE-2023-43525
6.7

CVE-2023-43525 is a buffer overflow vulnerability in Qualcomm audio drivers that allows memory corruption when copying sound model data from user to k...

May 6, 2024
CVE-2023-28772
6.7

A buffer overflow vulnerability in the Linux kernel's seq_buf_putmem_hex function allows local attackers to write beyond allocated memory boundaries. ...

Mar 23, 2023
CVE-2025-32732
6.6

A buffer overflow vulnerability in Intel QAT Windows software versions before 2.6.0 allows authenticated local users to cause denial of service. Attac...

Nov 11, 2025
CVE-2024-53013
6.6

This CVE describes a buffer overflow vulnerability in Qualcomm's voice call registration processing that could allow memory corruption. Attackers coul...

Jun 3, 2025
CVE-2025-67189
6.5

A buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to cause denial of service or potentially execute arbitrary code by...

Feb 3, 2026
CVE-2023-54328
6.5

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that allows attackers to crash the application...

Jan 13, 2026
CVE-2025-48721
6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. ...

Jan 2, 2026
CVE-2025-67074
6.5

A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by ...

Dec 17, 2025
CVE-2025-36917
6.5

This vulnerability in SwDcpItg of up_L2commonPdcpSecurity.cpp allows remote attackers to cause denial of service through an incorrect bounds check. It...

Dec 11, 2025
CVE-2025-65288
6.5

A buffer overflow vulnerability in Mercury MR816v2 routers allows attackers to crash devices or potentially execute arbitrary code by sending crafted ...

Dec 9, 2025
CVE-2025-65403
6.5

A buffer overflow vulnerability in LightFTP v2.0's g_cfg.MaxUsers component allows attackers to trigger a Denial of Service (DoS) by sending specially...

Dec 1, 2025
CVE-2025-65404
6.5

A buffer overflow vulnerability in Live555 Streaming Media's getSideInfo2() function allows attackers to cause denial of service by sending specially ...

Dec 1, 2025

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,245 CVEs classified as CWE-120, with 398 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free