CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,137
Total CVEs
338
Critical
629
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 82
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,137)

CVE-2023-39454
9.8

A buffer overflow vulnerability in ELECOM wireless LAN routers allows unauthenticated attackers to execute arbitrary code remotely. This affects users...

Aug 18, 2023
CVE-2023-39674
9.8

This CVE describes a buffer overflow vulnerability in D-Link DIR-880 routers via the fgets function. Successful exploitation could allow remote attack...

Aug 18, 2023
CVE-2023-39672
9.8

CVE-2023-39672 is a critical buffer overflow vulnerability in Tenda WH450 routers caused by improper bounds checking in the fgets function. This allow...

Aug 18, 2023
CVE-2023-39667
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected D-Link DIR-868L routers via a buffer overflow in the HTTP daemon. Att...

Aug 18, 2023
CVE-2023-39670
9.8

This CVE describes a buffer overflow vulnerability in Tenda AC6 routers via the fgets function. Attackers can exploit this to execute arbitrary code o...

Aug 18, 2023
CVE-2023-39665
9.8

This vulnerability in D-Link DIR-868L routers allows remote attackers to execute arbitrary code via a buffer overflow in the acStack_50 parameter. Att...

Aug 18, 2023
CVE-2023-29468
9.8

This vulnerability in Texas Instruments WiLink WL18xx MCP driver allows remote attackers to trigger a buffer overflow via specially crafted management...

Aug 14, 2023
CVE-2023-28561
9.8

CVE-2023-28561 is a critical memory corruption vulnerability in Qualcomm's QESL (Qualcomm Enhanced Sensor Layer) that allows attackers to execute arbi...

Aug 8, 2023
CVE-2023-39976
9.8

A buffer overflow vulnerability in libqb's log_blackbox.c allows attackers to execute arbitrary code by sending long log messages. This affects system...

Aug 8, 2023
CVE-2023-3346
9.8

A buffer overflow vulnerability in MITSUBISHI CNC Series allows remote unauthenticated attackers to send specially crafted packets that can cause deni...

Aug 3, 2023
CVE-2023-35980
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

Jul 25, 2023
CVE-2023-35982
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

Jul 25, 2023
CVE-2022-41793
9.8

This vulnerability allows arbitrary code execution through an out-of-bounds write in Open Babel's CSR format title functionality. Attackers can trigge...

Jul 21, 2023
CVE-2023-35802
9.8

CVE-2023-35802 is a critical buffer overflow vulnerability in the CAPWAP protocol implementation of IQ Engine on Extreme Network AP devices. Attackers...

Jul 15, 2023
CVE-2023-37793
9.8

CVE-2023-37793 is a critical buffer overflow vulnerability in WAYOS FBM-291W routers that allows remote attackers to execute arbitrary code or cause d...

Jul 14, 2023
CVE-2023-34561
9.8

A buffer overflow vulnerability in Geometry Dash's level parsing code allows attackers to execute arbitrary code by tricking users into loading malici...

Jul 11, 2023
CVE-2023-26612
9.8

CVE-2023-26612 is a critical buffer overflow vulnerability in D-Link DIR-823G routers that allows remote attackers to execute arbitrary code by sendin...

Jun 29, 2023
CVE-2023-26616
9.8

CVE-2023-26616 is a critical buffer overflow vulnerability in D-Link DIR-823G routers that allows remote attackers to execute arbitrary code or cause ...

Jun 29, 2023
CVE-2023-34563
9.8

This vulnerability allows authenticated attackers to execute arbitrary code on Netgear R6250 routers by exploiting a buffer overflow. Attackers who ga...

Jun 20, 2023
CVE-2020-20703
9.8

A buffer overflow vulnerability in VIM versions 8.1.2135 allows remote attackers to execute arbitrary code by exploiting the operand parameter. This a...

Jun 20, 2023
CVE-2023-35856
9.8

This vulnerability allows remote code execution in Mario Kart Wii game clients through a buffer overflow in network packet handling. Attackers can sen...

Jun 19, 2023
CVE-2023-34832
9.8

This CVE describes a buffer overflow vulnerability in TP-Link Archer AX10(EU) routers. Attackers can exploit this to execute arbitrary code or cause d...

Jun 16, 2023
CVE-2023-2686
9.8

A buffer overflow vulnerability in the Wi-Fi Commissioning example code in Silicon Labs Gecko SDK allows attackers to write arbitrary payloads onto th...

Jun 15, 2023
CVE-2023-1329
9.8

A buffer overflow vulnerability in HP multifunction printers running HP Workpath solutions could allow remote attackers to execute arbitrary code. Thi...

Jun 14, 2023
CVE-2021-45039
9.8

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code on Uniview IP cameras by exploiting a buffer overflow in...

May 31, 2023
CVE-2023-33009
9.8

A buffer overflow vulnerability in Zyxel firewall notification functions allows unauthenticated attackers to cause denial-of-service or execute arbitr...

May 24, 2023
CVE-2023-23300
9.8

CVE-2023-23300 is a buffer overflow vulnerability in Garmin Connect IQ's Toybox.Cryptography.Cipher.initialize API method that allows malicious applic...

May 23, 2023
CVE-2023-23302
9.8

CVE-2023-23302 is a critical buffer overflow vulnerability in Garmin's Connect IQ API that allows malicious applications to execute arbitrary code on ...

May 23, 2023
CVE-2023-22783
9.8

CVE-2023-22783 is a critical buffer overflow vulnerability in Aruba's PAPI protocol that allows unauthenticated attackers to execute arbitrary code wi...

May 8, 2023
CVE-2023-22785
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

May 8, 2023
CVE-2023-22779
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

May 8, 2023
CVE-2023-22781
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

May 8, 2023
CVE-2023-29856
9.8

CVE-2023-29856 is a critical buffer overflow vulnerability in the scandir.sgi binary of D-Link DIR-868L routers. This allows remote attackers to execu...

May 2, 2023
CVE-2023-27971
9.8

This CVE describes a critical buffer overflow vulnerability in certain HP LaserJet Pro printers that could allow remote attackers to execute arbitrary...

Apr 28, 2023
CVE-2023-28769
9.8

A buffer overflow vulnerability in the libclinkc.so library of the zhttpd web server on Zyxel DX5401-B0 devices allows remote unauthenticated attacker...

Apr 27, 2023
CVE-2023-30280
9.8

A buffer overflow vulnerability in Netgear R6900, R6700v3, and R6700 routers allows remote attackers to execute arbitrary code or cause denial of serv...

Apr 26, 2023
CVE-2022-33259
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected mobile devices by sending a specially crafted SMS message. It affects...

Apr 13, 2023
CVE-2022-25740
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected Qualcomm modem chipsets by exploiting a bu...

Apr 13, 2023
CVE-2022-25678
9.8

CVE-2022-25678 is a critical buffer overflow vulnerability in Qualcomm modem firmware that allows remote code execution. Attackers can exploit this by...

Apr 13, 2023
CVE-2023-28502
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Rocket Software's UniData and UniVerse database management systems. Attacke...

Mar 29, 2023
CVE-2023-28504
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Rocket Software's UniData and UniVerse database products. Attackers can exp...

Mar 29, 2023
CVE-2020-27507
9.8

CVE-2020-27507 is a critical buffer overflow vulnerability in Kamailio SIP servers before version 5.5.0. Attackers can crash the server or potentially...

Mar 15, 2023
CVE-2021-45423
9.8

A buffer overflow vulnerability in Pev 0.81 allows arbitrary code execution when processing malicious PE files. The vulnerability occurs due to improp...

Mar 13, 2023
CVE-2023-27061
9.8

This vulnerability in Tenda W15EV1 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a bu...

Mar 13, 2023
CVE-2023-27063
9.8

This vulnerability is a buffer overflow in Tenda W15EV1 routers via the DNSDomainName parameter in the formModifyDnsForward function. Attackers can ex...

Mar 13, 2023
CVE-2023-20032
9.8

A heap buffer overflow vulnerability in ClamAV's HFS+ partition file parser allows remote unauthenticated attackers to execute arbitrary code or cause...

Mar 1, 2023
CVE-2021-33226
9.8

CVE-2021-33226 is a buffer overflow vulnerability in SaltStack's status module that could allow remote code execution. The vulnerability affects SaltS...

Feb 17, 2023
CVE-2022-40514
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in...

Feb 12, 2023
CVE-2022-24324
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected IGSS Data Server systems by sending specially crafted messages that t...

Feb 1, 2023
CVE-2022-31209
9.8

This vulnerability in Infiray IRAY-A8Z3 thermal camera firmware allows remote attackers to execute arbitrary code via buffer overflow. Attackers can e...

Jul 17, 2022

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,137 CVEs classified as CWE-120, with 338 rated critical and 629 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free