CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,245)
A critical buffer overflow vulnerability in Totolink X2000R routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...
Jan 9, 2024This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WR840N routers via a buffer overflow in the password reset feature....
Apr 18, 2022This CVE describes a buffer overflow vulnerability in TP-LINK TL-WR840N routers via the DNSServers parameter. Attackers can exploit this to execute ar...
Mar 28, 2022This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR840N routers via a buffer overflow in the httpRemotePort paramete...
Mar 28, 2022Multiple buffer overflow vulnerabilities in HPE iLO Amplifier Pack allow highly privileged users to remotely execute arbitrary code. This affects all ...
Feb 24, 2022This vulnerability allows an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buff...
Aug 16, 2021This vulnerability is a buffer overflow in the big3d daemon on F5 BIG-IP DNS and GTM systems. It allows remote attackers to potentially execute arbitr...
Feb 12, 2021A Node.js vulnerability in the vm module's buffer allocation can expose uninitialized memory when timeouts interrupt allocations. This may leak sensit...
Jan 20, 2026A buffer overflow vulnerability in the PFCP library of open5gs allows a local attacker to execute arbitrary code or cause denial of service by providi...
Jun 18, 2025A buffer overflow vulnerability exists in D-LINK DI-8100 routers in the ipsec_road_asp function via the host_ip parameter. This allows attackers to po...
Apr 1, 2025A buffer overflow vulnerability in RTI Connext Professional's Persistence Service on non-Windows systems allows attackers to execute arbitrary code or...
Dec 13, 2024OnCell G3470A-LTE Series devices with firmware v1.7.7 and earlier have a buffer overflow vulnerability due to missing bounds checking. An attacker cou...
Jun 25, 2024A buffer overflow vulnerability in Samsung Exynos processors allows attackers to cause abnormal termination (crash) of mobile devices by sending speci...
Nov 8, 2023CVE-2023-4264 is a buffer overflow vulnerability in the Zephyr RTOS Bluetooth subsystem that could allow attackers to execute arbitrary code or cause ...
Sep 27, 2023Two buffer overflow vulnerabilities in the Zephyr eS-WiFi driver allow attackers to execute arbitrary code or cause denial of service by sending speci...
Sep 26, 2023An unauthenticated local attacker can cause Cisco NX-OS devices to crash and reload by entering a crafted string at the login prompt when TACACS+ or R...
Aug 23, 2023CVE-2022-24788 is a buffer overrun vulnerability in Vyper smart contract language where importing functions from JSON interfaces that return bytes gen...
Apr 13, 2022A buffer overflow vulnerability in stb_image.h's PNM loader incorrectly interprets 16-bit PGM files as 8-bit, causing memory corruption when convertin...
Oct 21, 2021A stack buffer overflow vulnerability in International Components for Unicode (ICU) allows local attackers to execute arbitrary code through the genrb...
May 27, 2025This CVE describes a buffer overflow vulnerability in Apple's web content processing components. Attackers can cause unexpected process crashes by tri...
Mar 31, 2025A buffer overflow vulnerability in ARM mbed-os v6.17.0 allows remote attackers to execute arbitrary code via crafted scripts targeting the hciTrSerial...
Apr 19, 2024This vulnerability in RedisBloom allows authenticated users to execute specially crafted CF.LOADCHUNK commands to trigger a heap overflow, potentially...
Apr 9, 2024This vulnerability in Eclipse ThreadX NetX Duo allows an attacker to cause an integer wrap-around in the __portable_aligned_alloc() function, leading ...
Mar 26, 2024This CVE involves two signed-to-unsigned conversion errors and buffer overflow vulnerabilities in Zephyr RTOS IPM drivers. Successful exploitation cou...
Sep 27, 2023This is a buffer overflow vulnerability in Eclipse OpenJ9's shared cache feature, which is enabled by default. Attackers could exploit this to cause d...
May 22, 2023This CVE describes a buffer overflow vulnerability in Huawei's HVB module due to insufficient data length verification. Attackers could exploit this t...
Aug 6, 2025A buffer overflow vulnerability in MuseScore Studio's GuitarPro file parser allows attackers to execute arbitrary code or crash the application by ope...
Mar 17, 2025This vulnerability allows attackers to crash systems by sending malformed glTF 3D model files to unpatched software. It affects any application using ...
Jan 8, 2025This vulnerability allows attackers to execute arbitrary code on Renesas SmartBond DA1469x devices by exploiting a buffer overflow in the bootrom's Fl...
Jul 10, 2024This vulnerability involves memory corruption in Qualcomm camera drivers when processing shared command buffer packets between userspace and kernel. I...
Jan 7, 2026This CVE describes a memory corruption vulnerability in Qualcomm hardware clock configuration parsing. Attackers could potentially execute arbitrary c...
Jan 7, 2026This vulnerability allows memory corruption during context user dumps due to insufficient buffer length validation. Attackers could potentially execut...
May 6, 2025A buffer overflow vulnerability in macOS allows applications with root privileges to execute arbitrary code with kernel privileges. This could lead to...
Jan 27, 2025CVE-2017-13308 is a buffer overflow vulnerability in MediaTek thermal sensor drivers that allows local privilege escalation. Attackers can exploit imp...
Dec 5, 2024This CVE describes a memory corruption vulnerability in Qualcomm's IPC frequency table parameter parsing for LPLH (likely Low Power Low Hardware). Whe...
Nov 4, 2024A buffer overflow vulnerability in specific camera drivers within XProtect Device Pack allows attackers with internal network access to execute arbitr...
Oct 8, 2024This CVE describes a memory corruption vulnerability in Qualcomm network scanning functionality that could allow an attacker to execute arbitrary code...
Oct 7, 2024This vulnerability allows memory corruption through IOCTL calls to the MSM module during audio operations on Qualcomm devices. Attackers could potenti...
Oct 7, 2024CVE-2023-43525 is a buffer overflow vulnerability in Qualcomm audio drivers that allows memory corruption when copying sound model data from user to k...
May 6, 2024A buffer overflow vulnerability in the Linux kernel's seq_buf_putmem_hex function allows local attackers to write beyond allocated memory boundaries. ...
Mar 23, 2023A buffer overflow vulnerability in Intel QAT Windows software versions before 2.6.0 allows authenticated local users to cause denial of service. Attac...
Nov 11, 2025This CVE describes a buffer overflow vulnerability in Qualcomm's voice call registration processing that could allow memory corruption. Attackers coul...
Jun 3, 2025A buffer overflow vulnerability in TOTOLINK A950RG routers allows remote attackers to cause denial of service or potentially execute arbitrary code by...
Feb 3, 2026AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that allows attackers to crash the application...
Jan 13, 2026A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. ...
Jan 2, 2026A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by ...
Dec 17, 2025This vulnerability in SwDcpItg of up_L2commonPdcpSecurity.cpp allows remote attackers to cause denial of service through an incorrect bounds check. It...
Dec 11, 2025A buffer overflow vulnerability in Mercury MR816v2 routers allows attackers to crash devices or potentially execute arbitrary code by sending crafted ...
Dec 9, 2025A buffer overflow vulnerability in LightFTP v2.0's g_cfg.MaxUsers component allows attackers to trigger a Denial of Service (DoS) by sending specially...
Dec 1, 2025A buffer overflow vulnerability in Live555 Streaming Media's getSideInfo2() function allows attackers to cause denial of service by sending specially ...
Dec 1, 2025About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,245 CVEs classified as CWE-120, with 398 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free