CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,253
Total CVEs
404
Critical
679
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 97
2 Tenda 59
3 Dlink 53
4 Totolink 52
5 Apple 48
6 Debian 41
7 Netgear 37
8 Linux 35
9 Fedoraproject 32
10 Google 22

All Buffer Copy without Size Check CVEs (1,253)

CVE-2024-44233
5.5

This vulnerability allows an attacker to cause a denial-of-service (system crash) by tricking a user into opening a maliciously crafted video file. It...

Nov 1, 2024
CVE-2024-44144
5.5

This CVE describes a buffer overflow vulnerability in Apple operating systems that could allow unexpected application termination when processing mali...

Oct 28, 2024
CVE-2024-48425
5.5

This CVE describes a null pointer dereference vulnerability in the Assimp library's mesh processing function that can cause segmentation faults. It af...

Oct 24, 2024
CVE-2024-9908
5.5

A critical buffer overflow vulnerability in D-Link DIR-619L B1 router's formSetMACFilter function allows attackers to execute arbitrary code by manipu...

Oct 13, 2024
CVE-2024-44160
5.5

A buffer overflow vulnerability in macOS texture processing allows maliciously crafted textures to cause unexpected application termination. This affe...

Sep 17, 2024
CVE-2024-40659
5.5

This vulnerability allows a local attacker to permanently disable AndroidKeyStore key generation by manipulating attestation keys through improper inp...

Sep 11, 2024
CVE-2024-42238
5.5

A buffer overflow vulnerability in the Linux kernel's Cirrus Logic CS_DSP firmware driver could allow local attackers to cause denial of service or po...

Aug 7, 2024
CVE-2022-48696
5.5

A buffer overflow vulnerability in the Linux kernel's regmap SPI subsystem could cause data corruption when SPI messages exceed maximum permitted size...

May 3, 2024
CVE-2023-26924
5.5

This CVE describes a segmentation fault vulnerability in LLVM's MLIR component when processing malicious input files. It primarily affects developers ...

Mar 27, 2023
CVE-2024-56805
5.4

A buffer overflow vulnerability in QNAP operating systems could allow authenticated remote attackers to modify memory or crash processes. This affects...

Jun 6, 2025
CVE-2025-29632
5.4

A buffer overflow vulnerability in Free5gc v4.0.0 allows remote attackers to cause denial of service by sending specially crafted messages to the AMF ...

May 29, 2025
CVE-2025-45864
5.4

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the addrPoolStart parameter in the formDhcpv6s interface. Attackers ...

May 13, 2025
CVE-2024-50839
5.4

A stored cross-site scripting (XSS) vulnerability in KASHIPARA E-learning Management System Project 1.0 allows remote attackers to inject malicious sc...

Nov 14, 2024
CVE-2024-29507
5.4

This CVE describes a stack-based buffer overflow vulnerability in Artifex Ghostscript when processing CIDFSubstPath and CIDFSubstFont parameters. Atta...

Jul 3, 2024
CVE-2024-37040
5.4

This CVE describes a classic buffer overflow vulnerability in Schneider Electric devices that allows authenticated users to crash the device by sendin...

Jun 12, 2024
CVE-2025-12440
5.3

This vulnerability in Google Chrome's Autofill feature allows a remote attacker to potentially extract sensitive information from browser memory by tr...

Nov 10, 2025
CVE-2025-41707
5.3

This CVE describes a denial-of-service vulnerability in a websocket handler where an unauthenticated remote attacker can send crafted websocket messag...

Oct 14, 2025
CVE-2025-41706
5.3

This CVE describes a denial-of-service vulnerability in a webserver where an unauthenticated remote attacker can craft a special GET request with an o...

Oct 14, 2025
CVE-2025-25280
5.3

A buffer overflow vulnerability in Century Systems' FutureNet AS series industrial routers and FA series protocol conversion machines allows remote un...

Mar 3, 2025
CVE-2024-24450
5.3

A stack-based buffer overflow vulnerability in OpenAirInterface's 5G AMF component allows remote attackers with N2 interface access to cause denial of...

Nov 15, 2024
CVE-2024-24447
5.3

A buffer overflow vulnerability in the OpenAirInterface 5G Core AMF component allows attackers to cause denial of service by sending a specially craft...

Nov 15, 2024
CVE-2024-35400
5.3

This vulnerability allows remote attackers to cause a stack overflow in TOTOLINK CP900L routers by sending specially crafted requests to the SetPortFo...

May 28, 2024
CVE-2024-35823
5.3

This CVE describes a buffer corruption vulnerability in the Linux kernel's virtual terminal (vt) subsystem when deleting Unicode characters. The issue...

May 17, 2024
CVE-2023-28904
5.2

This CVE describes a logic flaw in the MIB3 infotainment system bootloader that allows attackers with physical access to bypass firmware signature ver...

Jun 28, 2025
CVE-2021-46746
5.2

This vulnerability in AMD's ASP Secure OS Trusted Execution Environment (TEE) allows a privileged attacker with access to AMD signing keys to corrupt ...

Aug 13, 2024
CVE-2025-50361
5.1

A buffer overflow vulnerability exists in SmallBASIC's SDL implementation that could allow attackers to crash the application or potentially leak sens...

Dec 3, 2025
CVE-2025-25529
5.1

A buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 allows attackers to crash the device or execute arbitrary commands by exploiti...

Feb 11, 2025
CVE-2025-25525
5.1

A buffer overflow vulnerability in H3C FA3010L access points allows attackers to crash devices or execute arbitrary commands by sending specially craf...

Feb 11, 2025
CVE-2025-25527
5.1

A buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway allows attackers to crash the device or execute arbitrary commands by exploiting insuffi...

Feb 11, 2025
CVE-2024-54105
5.1

This CVE describes a buffer overflow vulnerability (CWE-120) in Huawei's image decoding module that allows attackers to cause denial of service throug...

Dec 12, 2024
CVE-2025-25900
4.9

A buffer overflow vulnerability exists in TP-Link TL-WR841ND V11 routers via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. Attac...

Feb 13, 2025
CVE-2024-9197
4.9

This is a post-authentication buffer overflow vulnerability in Zyxel VMG3625-T50B devices that allows authenticated administrators to cause temporary ...

Dec 3, 2024
CVE-2025-68114
4.8

This vulnerability in Capstone disassembly framework allows attackers to trigger stack buffer underflow or overflow by manipulating the vsnprintf retu...

Dec 17, 2025
CVE-2023-33302
4.7

This vulnerability allows authenticated attackers with regular webmail access to trigger a buffer overflow via crafted HTTP requests, potentially lead...

Mar 31, 2025
CVE-2025-25453
4.6

This vulnerability allows attackers to cause a buffer overflow in Tenda AC10 routers via the AdvSetMacMtuWan function's serviceName2 parameter. Succes...

Apr 15, 2025
CVE-2024-58109
4.6

A buffer overflow vulnerability exists in the codec module that could allow attackers to crash affected systems by sending specially crafted data. Thi...

Apr 7, 2025
CVE-2024-35106
4.6

A buffer overflow vulnerability exists in the NEXTU FLETA AX1500 WIFI6 router's web interface at /boafrm/formIpQoS. Attackers can exploit this via cra...

Feb 7, 2025
CVE-2022-49040
4.4

A buffer overflow vulnerability in Synology Drive Client allows local users with administrator privileges to crash the application. This affects users...

Sep 26, 2024
CVE-2025-65226
4.3

Tenda AC21 router firmware version V16.03.08.16 contains a buffer overflow vulnerability in the deviceId parameter of the /goform/saveParentControlInf...

Nov 20, 2025
CVE-2024-6352
4.3

A buffer overflow vulnerability in the APS layer of the Ember ZNet stack allows an attacker to cause an assert (crash) by sending a malformed packet. ...

Jan 13, 2025
CVE-2022-29974
4.3

This CVE describes a buffer overflow vulnerability in AMI's NTFS driver version 1.0.0, which could allow attackers to execute arbitrary code or cause ...

Dec 9, 2024
CVE-2022-20846
4.3

A heap buffer overflow vulnerability in Cisco Discovery Protocol (CDP) implementation for Cisco IOS XR Software allows unauthenticated adjacent attack...

Nov 15, 2024
CVE-2024-45619
4.3

A buffer handling vulnerability in OpenSC and related components allows attackers to access uninitialized memory via crafted USB devices or smart card...

Sep 3, 2024
CVE-2024-37571
4.3

A buffer overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or potentially leak sensitive information by ...

Jun 26, 2024
CVE-2025-43370
4.0

This vulnerability in Xcode involves improper path validation that can cause a process crash when processing an overly large path value. It affects de...

Sep 15, 2025
CVE-2025-43532
2.8

This CVE describes a memory corruption vulnerability in Apple operating systems caused by improper bounds checking. Processing malicious data could ca...

Dec 12, 2025
CVE-2026-24823
N/A

This CVE describes a classic buffer overflow vulnerability in the PNG decoding module of FASTSHIFT X-TRACK software. An attacker could exploit this by...

Jan 27, 2026
CVE-2026-24810
N/A

A buffer overflow vulnerability in RethinkDB's cJSON parsing module allows attackers to execute arbitrary code or crash the database service by sendin...

Jan 27, 2026
CVE-2026-24799
N/A

This CVE describes a classic buffer overflow vulnerability in dlib's zlib modules that allows attackers to write data beyond allocated buffer boundari...

Jan 27, 2026
CVE-2026-24800
N/A

This CVE describes a classic buffer overflow vulnerability in the zlib modules of tildearrow furnace software, specifically in the inflate.C file. An ...

Jan 27, 2026

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,253 CVEs classified as CWE-120, with 404 rated critical and 679 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free