CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,135
Total CVEs
336
Critical
629
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 82
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,135)

CVE-2024-35398
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK CP900L routers by exploiting a stack overflow in the setMacFilterRule...

May 28, 2024
CVE-2024-35571
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the formSetIptv function. Attacke...

May 20, 2024
CVE-2024-35099
9.8

This vulnerability is a stack overflow in the TOTOLINK LR350 router's loginAuth function, allowing remote attackers to execute arbitrary code by sendi...

May 14, 2024
CVE-2024-34945
9.8

A stack-based buffer overflow vulnerability in Tenda FH1206 routers allows remote attackers to execute arbitrary code by sending specially crafted req...

May 14, 2024
CVE-2024-33874
9.8

CVE-2024-33874 is a critical heap buffer overflow vulnerability in the HDF5 library's H5O__mtime_new_encode function. This allows attackers to execute...

May 14, 2024
CVE-2024-29159
9.8

CVE-2024-29159 is a critical buffer overflow vulnerability in HDF5's scaleoffset filter that can corrupt the instruction pointer. This allows attacker...

May 14, 2024
CVE-2024-27280
9.8

This CVE describes a buffer-overread vulnerability in Ruby's StringIO library where the ungetbyte and ungetc methods can read past string boundaries, ...

May 14, 2024
CVE-2022-32504
9.8

A stack buffer overflow vulnerability in Nuki smart lock devices allows remote code execution by sending specially crafted JSON objects via WebSocket....

May 14, 2024
CVE-2023-46012
9.8

A buffer overflow vulnerability in the LINKSYS EA7500 router's UPnP service allows remote attackers to execute arbitrary code via specially crafted HT...

May 7, 2024
CVE-2024-32017
9.8

CVE-2024-32017 is a critical buffer overflow vulnerability in RIOT OS's CoAP implementation affecting gcoap_dns_server_proxy_get() and _gcoap_forward_...

May 1, 2024
CVE-2024-30602
9.8

CVE-2024-30602 is a critical stack overflow vulnerability in Tenda FH1203 routers that allows remote attackers to execute arbitrary code by sending sp...

Mar 28, 2024
CVE-2024-30584
9.8

This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the vulnerability b...

Mar 28, 2024
CVE-2024-30593
9.8

This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote attackers to execute arbitrary code by sending specially ...

Mar 28, 2024
CVE-2024-29243
9.8

This vulnerability allows remote attackers to execute arbitrary code on Shenzhen Libituo Technology Co., Ltd LBT-T300-mini devices by exploiting a buf...

Mar 21, 2024
CVE-2024-28639
9.8

A buffer overflow vulnerability in TOTOLink routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially ...

Mar 16, 2024
CVE-2023-51885
9.8

A buffer overflow vulnerability in Mathtex v1.05 and earlier allows remote attackers to execute arbitrary code by sending specially crafted LaTeX stri...

Jan 24, 2024
CVE-2023-52103
9.8

This CVE-2023-52103 is a critical buffer overflow vulnerability in Huawei's FLP module that allows out-of-bounds read attacks. Successful exploitation...

Jan 16, 2024
CVE-2022-48620
9.8

CVE-2022-48620 is a buffer overflow vulnerability in uev (libuev) that occurs when epoll_wait is called with a large maxevents value. This allows atta...

Jan 12, 2024
CVE-2023-7221
9.8

This critical buffer overflow vulnerability in Totolink T6 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Jan 9, 2024
CVE-2023-33025
9.8

This vulnerability allows memory corruption in Qualcomm's Data Modem when processing a non-standard SDP body during a VoLTE call. Attackers could pote...

Jan 2, 2024
CVE-2023-51771
9.8

This vulnerability in MicroHttpServer allows a one-byte buffer overflow via a long URI in the _ParseHeader function. Attackers can exploit this to pot...

Dec 25, 2023
CVE-2023-7095
9.8

A critical buffer overflow vulnerability in Totolink A7100RU routers allows remote attackers to execute arbitrary code via specially crafted HTTP POST...

Dec 25, 2023
CVE-2023-50044
9.8

CVE-2023-50044 is an out-of-bounds read vulnerability in Cesanta MJS 2.20.0 that occurs when built-in API names appear as substrings in input strings....

Dec 20, 2023
CVE-2023-6906
9.8

This critical vulnerability allows remote attackers to execute arbitrary code on Totolink A7100RU routers by sending a specially crafted HTTP POST req...

Dec 18, 2023
CVE-2023-50469
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Shenzhen Libituo LBT-T300-T310 routers by sending specially crafted r...

Dec 15, 2023
CVE-2023-50245
9.8

OpenEXR-viewer versions before 0.6.1 contain a buffer overflow vulnerability (CWE-120) that could allow attackers to execute arbitrary code or cause d...

Dec 11, 2023
CVE-2023-41913
9.8

This vulnerability in strongSwan allows unauthenticated remote attackers to execute arbitrary code via a buffer overflow in the charon-tkm DH proxy. A...

Dec 7, 2023
CVE-2023-33082
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm Wi-Fi chipsets. It a...

Dec 5, 2023
CVE-2023-49208
9.8

A buffer overflow vulnerability in Glewlwyd SSO server's FIDO2 credential validation during WebAuthn registration allows attackers to execute arbitrar...

Nov 23, 2023
CVE-2023-38823
9.8

A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd se...

Nov 20, 2023
CVE-2023-45614
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

Nov 14, 2023
CVE-2023-45616
9.8

This CVE describes a critical buffer overflow vulnerability in Aruba's AirWave client service that allows unauthenticated attackers to execute arbitra...

Nov 14, 2023
CVE-2023-33045
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm WLAN firmware when p...

Nov 7, 2023
CVE-2023-42299
9.8

A buffer overflow vulnerability in OpenImageIO's read_subimage_data function allows remote attackers to execute arbitrary code or cause denial of serv...

Nov 2, 2023
CVE-2023-45797
9.8

This is a critical buffer overflow vulnerability in DreamSecurity MagicLine4NX software that allows remote attackers to execute arbitrary code on affe...

Oct 30, 2023
CVE-2018-17878
9.8

A buffer overflow vulnerability in certain ABUS TVIP cameras allows remote attackers to execute arbitrary code by sending specially crafted strings to...

Oct 26, 2023
CVE-2023-45199
9.8

This CVE describes a buffer overflow vulnerability in Mbed TLS that allows remote attackers to execute arbitrary code on affected systems. It affects ...

Oct 7, 2023
CVE-2023-35803
9.8

A buffer overflow vulnerability in IQ Engine on Extreme Network AP devices allows remote attackers to execute arbitrary code or cause denial of servic...

Oct 4, 2023
CVE-2023-40830
9.8

CVE-2023-40830 is a buffer overflow vulnerability in Tenda AC6 routers where the Index parameter lacks length validation. This allows attackers to exe...

Oct 3, 2023
CVE-2023-43131
9.8

General Device Manager 2.5.2.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code or crash the application. This...

Sep 25, 2023
CVE-2023-36109
9.8

A buffer overflow vulnerability in JerryScript 3.0's ecma_stringbuilder_append_raw component allows remote attackers to execute arbitrary code. This a...

Sep 20, 2023
CVE-2023-42320
9.8

A buffer overflow vulnerability in Tenda AC10V4 routers allows remote attackers to cause denial of service by sending specially crafted requests to th...

Sep 18, 2023
CVE-2020-19319
9.8

A buffer overflow vulnerability in D-Link DIR-619L B2 routers allows remote attackers to execute arbitrary code via the FILECODE parameter in the logi...

Sep 11, 2023
CVE-2023-42276
9.8

A buffer overflow vulnerability in hutool v5.8.21's jsonArray component allows attackers to execute arbitrary code or cause denial of service. This af...

Sep 8, 2023
CVE-2023-28562
9.8

CVE-2023-28562 is a critical buffer overflow vulnerability in Qualcomm chipsets that allows remote attackers to execute arbitrary code or cause denial...

Sep 5, 2023
CVE-2023-36187
9.8

A buffer overflow vulnerability in NETGEAR R6400v2 routers allows remote unauthenticated attackers to execute arbitrary code by sending a specially cr...

Sep 1, 2023
CVE-2023-41361
9.8

CVE-2023-41361 is a buffer overflow vulnerability in FRRouting's BGP daemon (bgpd) that occurs when processing BGP OPEN messages with overly large sof...

Aug 29, 2023
CVE-2023-4041
9.8

This critical vulnerability in Silicon Labs Gecko Bootloader allows attackers to execute arbitrary code and bypass authentication by exploiting buffer...

Aug 23, 2023
CVE-2023-39747
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected TP-Link wireless routers via a buffer overflow in the radiusSecret pa...

Aug 21, 2023
CVE-2023-39749
9.8

CVE-2023-39749 is a critical buffer overflow vulnerability in D-Link DAP-2660 access points that allows remote attackers to execute arbitrary code or ...

Aug 21, 2023

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,135 CVEs classified as CWE-120, with 336 rated critical and 629 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free