CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,249
Total CVEs
402
Critical
677
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 96
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 48
6 Debian 41
7 Netgear 37
8 Linux 35
9 Fedoraproject 32
10 Google 22

All Buffer Copy without Size Check CVEs (1,249)

CVE-2025-25523
5.9

A buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch allows attackers to execute arbitrary code by exploiting insufficient input val...

Feb 11, 2025
CVE-2024-56914
5.7

A buffer overflow vulnerability exists in the D-Link DSL-3782 router's Parental Control web interface. Attackers can exploit this by sending specially...

Jan 22, 2025
CVE-2020-6923
5.7

CVE-2020-6923 is a buffer overflow vulnerability in HP Linux Imaging and Printing (HPLIP) software that could allow attackers to execute arbitrary cod...

Dec 19, 2024
CVE-2024-52711
5.7

A buffer overflow vulnerability exists in the ip_position_asp function of DI-8100 firmware via the ip parameter. This could allow attackers to execute...

Nov 19, 2024
CVE-2024-52024
5.7

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request that tr...

Nov 5, 2024
CVE-2024-52026
5.7

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request that tr...

Nov 5, 2024
CVE-2024-52029
5.7

This vulnerability in Netgear R7000P routers allows attackers to trigger a stack overflow via the pptp_user_netmask parameter in the genie_pptp.cgi sc...

Nov 5, 2024
CVE-2024-52013
5.7

This vulnerability is a stack overflow in Netgear routers' pptp_user_ip parameter at wiz_pptp.cgi. Attackers can exploit it via crafted POST requests ...

Nov 5, 2024
CVE-2024-52015
5.7

This vulnerability is a stack overflow in specific Netgear router models via the pptp_user_ip parameter in the bsw_pptp.cgi script. Attackers can expl...

Nov 5, 2024
CVE-2024-52017
5.7

This vulnerability in Netgear XR300 routers allows attackers to trigger a stack overflow via the passphrase parameter in bridge_wireless_main.cgi, lea...

Nov 5, 2024
CVE-2024-51012
5.7

This vulnerability in Netgear R8500 routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the ipv...

Nov 5, 2024
CVE-2024-51014
5.7

CVE-2024-51014 is a stack overflow vulnerability in Netgear XR300 routers that allows attackers to cause a Denial of Service (DoS) by sending a specia...

Nov 5, 2024
CVE-2024-51016
5.7

Netgear XR300 routers running firmware v1.0.3.78 contain a stack buffer overflow vulnerability in the usb_approve.cgi component. Attackers can exploit...

Nov 5, 2024
CVE-2024-51018
5.7

This vulnerability in Netgear R7000P routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the pp...

Nov 5, 2024
CVE-2024-51020
5.7

This vulnerability in Netgear R7000P routers allows attackers to trigger a stack overflow via the apn parameter in usbISP_detail_edit.cgi, leading to ...

Nov 5, 2024
CVE-2024-51001
5.7

This vulnerability in Netgear R8500 routers allows attackers to trigger a stack overflow via the sysDNSHost parameter in ddns.cgi, causing a Denial of...

Nov 5, 2024
CVE-2024-51003
5.7

Multiple Netgear router models contain stack overflow vulnerabilities in the ap_mode.cgi component via DNS parameters. Attackers can exploit these vul...

Nov 5, 2024
CVE-2024-51007
5.7

This vulnerability allows attackers to cause a Denial of Service (DoS) on Netgear XR300 routers by sending a specially crafted POST request to the wir...

Nov 5, 2024
CVE-2024-50995
5.7

This vulnerability in Netgear R8500 routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the usb...

Nov 5, 2024
CVE-2024-50997
5.7

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request to the ...

Nov 5, 2024
CVE-2024-50999
5.7

This CVE describes a command injection vulnerability in Netgear R8500 routers where attackers can execute arbitrary operating system commands by sendi...

Nov 5, 2024
CVE-2024-33876
5.7

CVE-2024-33876 is a heap buffer overflow vulnerability in the HDF5 library's H5S__point_deserialize function. This allows attackers to potentially exe...

May 14, 2024
CVE-2024-29166
5.7

CVE-2024-29166 is a buffer overflow vulnerability in HDF5 library versions through 1.14.3 that can corrupt the instruction pointer when processing spe...

May 14, 2024
CVE-2025-57569
5.6

This CVE describes a buffer overflow vulnerability in Tenda F3 routers through the portList parameter in the /goform/setNAT endpoint. Attackers could ...

Sep 10, 2025
CVE-2025-57570
5.6

This vulnerability allows attackers to execute arbitrary code or cause denial of service on Tenda F3 routers by sending specially crafted requests to ...

Sep 10, 2025
CVE-2025-57571
5.6

This CVE describes a buffer overflow vulnerability in Tenda F3 routers via the macFilterList parameter in the goform/setNAT endpoint. Attackers can po...

Sep 10, 2025
CVE-2025-57572
5.6

This CVE describes a buffer overflow vulnerability in Tenda F3 routers via the onlineList parameter in the setParentControl form handler. Attackers co...

Sep 10, 2025
CVE-2025-57573
5.6

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on Tenda F3 routers via a buffer overflow in the wifiT...

Sep 10, 2025
CVE-2013-1424
5.6

This CVE describes a buffer overflow vulnerability in matplotlib that could allow attackers to execute arbitrary code or cause denial of service. It a...

Jun 26, 2025
CVE-2025-24157
5.6

This CVE describes a buffer overflow vulnerability in macOS kernel memory handling that could allow a malicious application to cause system crashes or...

Mar 31, 2025
CVE-2025-28162
5.5

A buffer overflow vulnerability in libpng versions 1.6.43 through 1.6.46 allows local attackers to cause denial of service through memory exhaustion. ...

Jan 27, 2026
CVE-2022-50687
5.5

CVE-2022-50687 is a buffer overflow vulnerability in Cobian Backup 11 Gravity that allows attackers to crash the application by pasting a specially cr...

Dec 22, 2025
CVE-2025-57275
5.5

CVE-2025-57275 is a buffer overflow vulnerability in the NVMe-oF target component of SPDK 25.05 that could allow attackers to crash the service or pot...

Oct 1, 2025
CVE-2025-43312
5.5

A buffer overflow vulnerability in macOS allows malicious applications to cause system crashes (kernel panics). This affects macOS systems running ver...

Sep 15, 2025
CVE-2025-26434
5.5

This CVE describes a buffer overflow vulnerability in libxml2 that allows an out-of-bounds read, potentially leading to local information disclosure w...

Sep 5, 2025
CVE-2025-27072
5.5

This vulnerability allows information disclosure when processing Ethernet AVB (Audio Video Bridging) packets with invalid header lengths on Qualcomm c...

Aug 6, 2025
CVE-2025-29480
5.5

A buffer overflow vulnerability in GDAL 3.10.2's OGRSpatialReference::Release function allows a local attacker to cause denial of service by crashing ...

Apr 7, 2025
CVE-2025-29476
5.5

A buffer overflow vulnerability exists in the compress_chunk_fuzzer component of c-blosc2, a high-performance compression library. This vulnerability ...

Apr 4, 2025
CVE-2024-57184
5.5

A heap-based buffer overflow vulnerability exists in GPAC v0.8.0's MP4Box tool when processing crafted MP4 files. This can cause denial of service (cr...

Jan 24, 2025
CVE-2024-57543
5.5

A buffer overflow vulnerability exists in the Linksys E8450 router firmware where the dhcpstart_ip field is copied to the stack without length verific...

Jan 21, 2025
CVE-2024-57545
5.5

A buffer overflow vulnerability exists in Linksys E8450 routers where the hidden_dhcp_num field is copied to the stack without length verification. Th...

Jan 21, 2025
CVE-2024-53681
5.5

A buffer overflow vulnerability exists in the Linux kernel's NVMe over Fabrics target subsystem (nvmet). When processing subsystem NQN (NVMe Qualified...

Jan 15, 2025
CVE-2024-56454
5.5

This vulnerability allows attackers to crash systems by sending malformed glTF 3D model files to unpatched software. It affects any application using ...

Jan 8, 2025
CVE-2024-56452
5.5

This vulnerability allows attackers to crash applications by providing malicious glTF 3D model files that trigger buffer overflows during parsing. It ...

Jan 8, 2025
CVE-2024-46657
5.5

CVE-2024-46657 is a buffer overflow vulnerability in Artifex Software mupdf's pdfextract tool that allows attackers to cause a Denial of Service (DoS)...

Dec 10, 2024
CVE-2024-50090
5.5

A buffer overflow vulnerability in the Linux kernel's Intel Xe GPU driver allows local attackers to cause kernel crashes or potentially execute arbitr...

Nov 5, 2024
CVE-2024-44233
5.5

This vulnerability allows an attacker to cause a denial-of-service (system crash) by tricking a user into opening a maliciously crafted video file. It...

Nov 1, 2024
CVE-2024-44144
5.5

This CVE describes a buffer overflow vulnerability in Apple operating systems that could allow unexpected application termination when processing mali...

Oct 28, 2024
CVE-2024-48425
5.5

This CVE describes a null pointer dereference vulnerability in the Assimp library's mesh processing function that can cause segmentation faults. It af...

Oct 24, 2024
CVE-2024-9908
5.5

A critical buffer overflow vulnerability in D-Link DIR-619L B1 router's formSetMACFilter function allows attackers to execute arbitrary code by manipu...

Oct 13, 2024

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,249 CVEs classified as CWE-120, with 402 rated critical and 677 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free