CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,249
Total CVEs
402
Critical
677
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 96
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 48
6 Debian 41
7 Netgear 37
8 Linux 35
9 Fedoraproject 32
10 Google 22

All Buffer Copy without Size Check CVEs (1,249)

CVE-2025-36917
6.5

This vulnerability in SwDcpItg of up_L2commonPdcpSecurity.cpp allows remote attackers to cause denial of service through an incorrect bounds check. It...

Dec 11, 2025
CVE-2025-65288
6.5

A buffer overflow vulnerability in Mercury MR816v2 routers allows attackers to crash devices or potentially execute arbitrary code by sending crafted ...

Dec 9, 2025
CVE-2025-65403
6.5

A buffer overflow vulnerability in LightFTP v2.0's g_cfg.MaxUsers component allows attackers to trigger a Denial of Service (DoS) by sending specially...

Dec 1, 2025
CVE-2025-65404
6.5

A buffer overflow vulnerability in Live555 Streaming Media's getSideInfo2() function allows attackers to cause denial of service by sending specially ...

Dec 1, 2025
CVE-2025-24519
6.5

A buffer overflow vulnerability in Intel QAT Windows software allows authenticated local attackers to escalate privileges and manipulate data. This af...

Nov 11, 2025
CVE-2025-33131
6.5

This vulnerability in IBM DB2 High Performance Unload allows authenticated users to trigger a stack-based buffer overflow, causing the program to cras...

Oct 28, 2025
CVE-2025-20149
6.5

A buffer overflow vulnerability in Cisco IOS and IOS XE CLI allows authenticated local attackers with low privileges to execute crafted commands that ...

Sep 24, 2025
CVE-2025-55495
6.5

This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the fromSe...

Aug 27, 2025
CVE-2025-51823
6.5

CVE-2025-51823 is a buffer overflow vulnerability in libcsp 2.0's csp_eth_init() function that occurs when copying interface names without length vali...

Aug 11, 2025
CVE-2025-51824
6.5

CVE-2025-51824 is a buffer overflow vulnerability in libcsp 2.0's csp_usart_open() function that could allow attackers to execute arbitrary code or ca...

Aug 11, 2025
CVE-2025-46785
6.5

A buffer over-read vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network access. This...

May 14, 2025
CVE-2025-25505
6.5

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafte...

Feb 21, 2025
CVE-2025-25510
6.5

A buffer overflow vulnerability in Tenda AC8 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafte...

Feb 21, 2025
CVE-2024-57513
6.5

A floating-point exception vulnerability in Bento4's AP4_TfraAtom function allows attackers to cause denial of service by crashing applications that p...

Jan 29, 2025
CVE-2024-57540
6.5

A buffer overflow vulnerability exists in Linksys E8450 routers where the 'action' field is copied to the stack without length verification. This allo...

Jan 21, 2025
CVE-2024-37606
6.5

A stack overflow vulnerability in D-Link DCS-932L IP cameras allows attackers to cause denial of service via specially crafted HTTP requests. This aff...

Dec 17, 2024
CVE-2024-37050
6.5

This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows remote attackers with administrator access to execute arbitra...

Nov 22, 2024
CVE-2024-41206
6.5

A stack-based buffer over-read vulnerability in tsMuxer allows attackers to read beyond allocated memory boundaries when processing specially crafted ...

Nov 14, 2024
CVE-2024-50956
6.5

A buffer overflow vulnerability in the RecvSocketData function of Inovance AM400 series PLCs allows attackers to cause denial of service or execute ar...

Nov 13, 2024
CVE-2024-48712
6.5

This vulnerability in TP-Link TL-WDR7660 routers allows attackers to cause a stack overflow by sending specially crafted requests to the rtRuleJsonToB...

Oct 15, 2024
CVE-2024-48714
6.5

This vulnerability in TP-Link TL-WDR7660 routers allows attackers to trigger a stack overflow by sending specially crafted requests to the guest netwo...

Oct 15, 2024
CVE-2024-24972
6.5

A buffer overflow vulnerability (CWE-120) in Gallagher Controller 6000/7000 diagnostic web interface allows authenticated operators to reboot controll...

Sep 11, 2024
CVE-2024-39538
6.5

An unauthenticated adjacent attacker can cause a Denial-of-Service (DoS) on Juniper ACX7000 Series routers by sending specific multicast traffic that ...

Jul 11, 2024
CVE-2024-39181
6.5

A buffer overflow vulnerability exists in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 routers version 3.2. Attackers can exploit this by sendin...

Jul 9, 2024
CVE-2024-5463
6.5

A classic buffer overflow vulnerability in the login component of Synology camera firmware allows remote attackers to write specific non-sensitive fil...

Jun 4, 2024
CVE-2024-33809
6.5

CVE-2024-33809 is a buffer overflow vulnerability in PingCAP TiDB v7.5.1 that could allow attackers to cause database crashes and denial of service. T...

May 24, 2024
CVE-2023-37929
6.5

A buffer overflow vulnerability in the CGI program of Zyxel VMG3625-T50B firmware allows authenticated remote attackers to cause denial of service (Do...

May 21, 2024
CVE-2024-33771
6.5

A buffer overflow vulnerability in the D-Link DIR-619L Rev.B router's web interface allows authenticated remote attackers to cause a denial of service...

May 14, 2024
CVE-2024-33773
6.5

A buffer overflow vulnerability in the /bin/boa web server component on D-Link DIR-619L Rev.B routers allows authenticated remote attackers to cause d...

May 14, 2024
CVE-2024-33783
6.5

CVE-2024-33783 is a buffer overflow vulnerability in MP-SPDZ v0.3.8's SilentPprf.cpp that allows attackers to trigger a segmentation fault via crafted...

May 7, 2024
CVE-2022-43391
6.5

A buffer overflow vulnerability in the CGI program of Zyxel NR7101 firmware allows authenticated attackers to cause denial-of-service conditions by se...

Jan 11, 2023
CVE-2025-46776
6.4

This CVE describes a classic buffer overflow vulnerability in Fortinet FortiExtender devices that allows authenticated users to execute arbitrary code...

Nov 18, 2025
CVE-2024-27129
6.4

This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows authenticated attackers to execute arbitrary code remotely. I...

May 21, 2024
CVE-2024-31963
6.4

This vulnerability allows an authenticated attacker to conduct a buffer overflow attack on affected Mitel SIP phones and conference units, potentially...

May 2, 2024
CVE-2025-48386
6.3

This CVE describes a buffer overflow vulnerability in Git's wincred credential helper on Windows systems. The helper uses a static buffer without prop...

Jul 8, 2025
CVE-2024-57537
6.3

A buffer overflow vulnerability in Linksys E8450 routers allows attackers to execute arbitrary code by sending specially crafted requests. This affect...

Jan 21, 2025
CVE-2024-56450
6.3

A buffer overflow vulnerability in a driver module allows attackers to crash affected systems, potentially causing denial of service. This affects Hua...

Jan 8, 2025
CVE-2024-7217
6.3

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary code via a buffer overflow in the login authent...

Jul 30, 2024
CVE-2019-25326
6.2

CVE-2019-25326 is a buffer overflow vulnerability in ipPulse 1.92 that allows local attackers to cause denial of service by crashing the application. ...

Feb 18, 2026
CVE-2020-37171
6.2

CVE-2020-37171 is a buffer overflow vulnerability in TapinRadio's proxy username configuration that allows local attackers to crash the application vi...

Feb 7, 2026
CVE-2020-37165
6.2

CVE-2020-37165 is a buffer overflow vulnerability in AbsoluteTelnet that allows local attackers to crash the application by supplying an oversized lic...

Feb 7, 2026
CVE-2022-50689
6.2

CVE-2022-50689 is a buffer overflow vulnerability in Cobian Reflector 0.9.93 RC1 that allows attackers to crash the application by pasting a large 800...

Dec 22, 2025
CVE-2025-29482
6.2

A buffer overflow vulnerability in libheif 1.19.7 allows local attackers to execute arbitrary code through SAO processing in libde265. This affects sy...

Apr 7, 2025
CVE-2024-53426
6.2

A heap buffer overflow vulnerability in ntopng's MDNS packet dissection function allows attackers to execute arbitrary code or cause denial of service...

Nov 21, 2024
CVE-2024-35420
6.2

CVE-2024-35420 is a heap overflow vulnerability in wac (WebAssembly Compiler) that allows attackers to write beyond allocated memory boundaries. This ...

Nov 8, 2024
CVE-2024-35418
6.2

CVE-2024-35418 is a heap overflow vulnerability in wac's setup_call function that allows attackers to cause Denial of Service (DoS) by providing a mal...

Nov 8, 2024
CVE-2024-45184
6.2

This vulnerability is a heap buffer overflow in Samsung's USAT component affecting multiple Exynos chipsets used in mobile devices, wearables, and mod...

Oct 11, 2024
CVE-2025-12142
6.1

A buffer overflow vulnerability in ABB Terra AC wallbox charging stations allows attackers to execute arbitrary code or cause denial of service by sen...

Oct 29, 2025
CVE-2025-7677
5.9

This vulnerability in ASPECT software allows unauthorized users with local network access to cause a denial-of-service through a buffer copy issue tha...

Aug 11, 2025
CVE-2024-24456
5.9

A buffer overflow vulnerability in Athonet MME allows remote attackers to crash the system by sending a malformed E-RAB Release Command packet. This a...

Mar 31, 2025

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,249 CVEs classified as CWE-120, with 402 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free