CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,135)
This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK CP900L routers by exploiting a stack overflow in the setMacFilterRule...
May 28, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the formSetIptv function. Attacke...
May 20, 2024This vulnerability is a stack overflow in the TOTOLINK LR350 router's loginAuth function, allowing remote attackers to execute arbitrary code by sendi...
May 14, 2024A stack-based buffer overflow vulnerability in Tenda FH1206 routers allows remote attackers to execute arbitrary code by sending specially crafted req...
May 14, 2024CVE-2024-33874 is a critical heap buffer overflow vulnerability in the HDF5 library's H5O__mtime_new_encode function. This allows attackers to execute...
May 14, 2024CVE-2024-29159 is a critical buffer overflow vulnerability in HDF5's scaleoffset filter that can corrupt the instruction pointer. This allows attacker...
May 14, 2024This CVE describes a buffer-overread vulnerability in Ruby's StringIO library where the ungetbyte and ungetc methods can read past string boundaries, ...
May 14, 2024A stack buffer overflow vulnerability in Nuki smart lock devices allows remote code execution by sending specially crafted JSON objects via WebSocket....
May 14, 2024A buffer overflow vulnerability in the LINKSYS EA7500 router's UPnP service allows remote attackers to execute arbitrary code via specially crafted HT...
May 7, 2024CVE-2024-32017 is a critical buffer overflow vulnerability in RIOT OS's CoAP implementation affecting gcoap_dns_server_proxy_get() and _gcoap_forward_...
May 1, 2024CVE-2024-30602 is a critical stack overflow vulnerability in Tenda FH1203 routers that allows remote attackers to execute arbitrary code by sending sp...
Mar 28, 2024This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the vulnerability b...
Mar 28, 2024This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote attackers to execute arbitrary code by sending specially ...
Mar 28, 2024This vulnerability allows remote attackers to execute arbitrary code on Shenzhen Libituo Technology Co., Ltd LBT-T300-mini devices by exploiting a buf...
Mar 21, 2024A buffer overflow vulnerability in TOTOLink routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially ...
Mar 16, 2024A buffer overflow vulnerability in Mathtex v1.05 and earlier allows remote attackers to execute arbitrary code by sending specially crafted LaTeX stri...
Jan 24, 2024This CVE-2023-52103 is a critical buffer overflow vulnerability in Huawei's FLP module that allows out-of-bounds read attacks. Successful exploitation...
Jan 16, 2024CVE-2022-48620 is a buffer overflow vulnerability in uev (libuev) that occurs when epoll_wait is called with a large maxevents value. This allows atta...
Jan 12, 2024This critical buffer overflow vulnerability in Totolink T6 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...
Jan 9, 2024This vulnerability allows memory corruption in Qualcomm's Data Modem when processing a non-standard SDP body during a VoLTE call. Attackers could pote...
Jan 2, 2024This vulnerability in MicroHttpServer allows a one-byte buffer overflow via a long URI in the _ParseHeader function. Attackers can exploit this to pot...
Dec 25, 2023A critical buffer overflow vulnerability in Totolink A7100RU routers allows remote attackers to execute arbitrary code via specially crafted HTTP POST...
Dec 25, 2023CVE-2023-50044 is an out-of-bounds read vulnerability in Cesanta MJS 2.20.0 that occurs when built-in API names appear as substrings in input strings....
Dec 20, 2023This critical vulnerability allows remote attackers to execute arbitrary code on Totolink A7100RU routers by sending a specially crafted HTTP POST req...
Dec 18, 2023This vulnerability allows remote attackers to execute arbitrary code on affected Shenzhen Libituo LBT-T300-T310 routers by sending specially crafted r...
Dec 15, 2023OpenEXR-viewer versions before 0.6.1 contain a buffer overflow vulnerability (CWE-120) that could allow attackers to execute arbitrary code or cause d...
Dec 11, 2023This vulnerability in strongSwan allows unauthenticated remote attackers to execute arbitrary code via a buffer overflow in the charon-tkm DH proxy. A...
Dec 7, 2023This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm Wi-Fi chipsets. It a...
Dec 5, 2023A buffer overflow vulnerability in Glewlwyd SSO server's FIDO2 credential validation during WebAuthn registration allows attackers to execute arbitrar...
Nov 23, 2023A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd se...
Nov 20, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
Nov 14, 2023This CVE describes a critical buffer overflow vulnerability in Aruba's AirWave client service that allows unauthenticated attackers to execute arbitra...
Nov 14, 2023This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm WLAN firmware when p...
Nov 7, 2023A buffer overflow vulnerability in OpenImageIO's read_subimage_data function allows remote attackers to execute arbitrary code or cause denial of serv...
Nov 2, 2023This is a critical buffer overflow vulnerability in DreamSecurity MagicLine4NX software that allows remote attackers to execute arbitrary code on affe...
Oct 30, 2023A buffer overflow vulnerability in certain ABUS TVIP cameras allows remote attackers to execute arbitrary code by sending specially crafted strings to...
Oct 26, 2023This CVE describes a buffer overflow vulnerability in Mbed TLS that allows remote attackers to execute arbitrary code on affected systems. It affects ...
Oct 7, 2023A buffer overflow vulnerability in IQ Engine on Extreme Network AP devices allows remote attackers to execute arbitrary code or cause denial of servic...
Oct 4, 2023CVE-2023-40830 is a buffer overflow vulnerability in Tenda AC6 routers where the Index parameter lacks length validation. This allows attackers to exe...
Oct 3, 2023General Device Manager 2.5.2.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code or crash the application. This...
Sep 25, 2023A buffer overflow vulnerability in JerryScript 3.0's ecma_stringbuilder_append_raw component allows remote attackers to execute arbitrary code. This a...
Sep 20, 2023A buffer overflow vulnerability in Tenda AC10V4 routers allows remote attackers to cause denial of service by sending specially crafted requests to th...
Sep 18, 2023A buffer overflow vulnerability in D-Link DIR-619L B2 routers allows remote attackers to execute arbitrary code via the FILECODE parameter in the logi...
Sep 11, 2023A buffer overflow vulnerability in hutool v5.8.21's jsonArray component allows attackers to execute arbitrary code or cause denial of service. This af...
Sep 8, 2023CVE-2023-28562 is a critical buffer overflow vulnerability in Qualcomm chipsets that allows remote attackers to execute arbitrary code or cause denial...
Sep 5, 2023A buffer overflow vulnerability in NETGEAR R6400v2 routers allows remote unauthenticated attackers to execute arbitrary code by sending a specially cr...
Sep 1, 2023CVE-2023-41361 is a buffer overflow vulnerability in FRRouting's BGP daemon (bgpd) that occurs when processing BGP OPEN messages with overly large sof...
Aug 29, 2023This critical vulnerability in Silicon Labs Gecko Bootloader allows attackers to execute arbitrary code and bypass authentication by exploiting buffer...
Aug 23, 2023This vulnerability allows remote attackers to execute arbitrary code on affected TP-Link wireless routers via a buffer overflow in the radiusSecret pa...
Aug 21, 2023CVE-2023-39749 is a critical buffer overflow vulnerability in D-Link DAP-2660 access points that allows remote attackers to execute arbitrary code or ...
Aug 21, 2023About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,135 CVEs classified as CWE-120, with 336 rated critical and 629 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free