CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,137)
A buffer overflow vulnerability in ELECOM wireless LAN routers allows unauthenticated attackers to execute arbitrary code remotely. This affects users...
Aug 18, 2023This CVE describes a buffer overflow vulnerability in D-Link DIR-880 routers via the fgets function. Successful exploitation could allow remote attack...
Aug 18, 2023CVE-2023-39672 is a critical buffer overflow vulnerability in Tenda WH450 routers caused by improper bounds checking in the fgets function. This allow...
Aug 18, 2023This vulnerability allows remote attackers to execute arbitrary code on affected D-Link DIR-868L routers via a buffer overflow in the HTTP daemon. Att...
Aug 18, 2023This CVE describes a buffer overflow vulnerability in Tenda AC6 routers via the fgets function. Attackers can exploit this to execute arbitrary code o...
Aug 18, 2023This vulnerability in D-Link DIR-868L routers allows remote attackers to execute arbitrary code via a buffer overflow in the acStack_50 parameter. Att...
Aug 18, 2023This vulnerability in Texas Instruments WiLink WL18xx MCP driver allows remote attackers to trigger a buffer overflow via specially crafted management...
Aug 14, 2023CVE-2023-28561 is a critical memory corruption vulnerability in Qualcomm's QESL (Qualcomm Enhanced Sensor Layer) that allows attackers to execute arbi...
Aug 8, 2023A buffer overflow vulnerability in libqb's log_blackbox.c allows attackers to execute arbitrary code by sending long log messages. This affects system...
Aug 8, 2023A buffer overflow vulnerability in MITSUBISHI CNC Series allows remote unauthenticated attackers to send specially crafted packets that can cause deni...
Aug 3, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
Jul 25, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
Jul 25, 2023This vulnerability allows arbitrary code execution through an out-of-bounds write in Open Babel's CSR format title functionality. Attackers can trigge...
Jul 21, 2023CVE-2023-35802 is a critical buffer overflow vulnerability in the CAPWAP protocol implementation of IQ Engine on Extreme Network AP devices. Attackers...
Jul 15, 2023CVE-2023-37793 is a critical buffer overflow vulnerability in WAYOS FBM-291W routers that allows remote attackers to execute arbitrary code or cause d...
Jul 14, 2023A buffer overflow vulnerability in Geometry Dash's level parsing code allows attackers to execute arbitrary code by tricking users into loading malici...
Jul 11, 2023CVE-2023-26612 is a critical buffer overflow vulnerability in D-Link DIR-823G routers that allows remote attackers to execute arbitrary code by sendin...
Jun 29, 2023CVE-2023-26616 is a critical buffer overflow vulnerability in D-Link DIR-823G routers that allows remote attackers to execute arbitrary code or cause ...
Jun 29, 2023This vulnerability allows authenticated attackers to execute arbitrary code on Netgear R6250 routers by exploiting a buffer overflow. Attackers who ga...
Jun 20, 2023A buffer overflow vulnerability in VIM versions 8.1.2135 allows remote attackers to execute arbitrary code by exploiting the operand parameter. This a...
Jun 20, 2023This vulnerability allows remote code execution in Mario Kart Wii game clients through a buffer overflow in network packet handling. Attackers can sen...
Jun 19, 2023This CVE describes a buffer overflow vulnerability in TP-Link Archer AX10(EU) routers. Attackers can exploit this to execute arbitrary code or cause d...
Jun 16, 2023A buffer overflow vulnerability in the Wi-Fi Commissioning example code in Silicon Labs Gecko SDK allows attackers to write arbitrary payloads onto th...
Jun 15, 2023A buffer overflow vulnerability in HP multifunction printers running HP Workpath solutions could allow remote attackers to execute arbitrary code. Thi...
Jun 14, 2023This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code on Uniview IP cameras by exploiting a buffer overflow in...
May 31, 2023A buffer overflow vulnerability in Zyxel firewall notification functions allows unauthenticated attackers to cause denial-of-service or execute arbitr...
May 24, 2023CVE-2023-23300 is a buffer overflow vulnerability in Garmin Connect IQ's Toybox.Cryptography.Cipher.initialize API method that allows malicious applic...
May 23, 2023CVE-2023-23302 is a critical buffer overflow vulnerability in Garmin's Connect IQ API that allows malicious applications to execute arbitrary code on ...
May 23, 2023CVE-2023-22783 is a critical buffer overflow vulnerability in Aruba's PAPI protocol that allows unauthenticated attackers to execute arbitrary code wi...
May 8, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
May 8, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
May 8, 2023This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...
May 8, 2023CVE-2023-29856 is a critical buffer overflow vulnerability in the scandir.sgi binary of D-Link DIR-868L routers. This allows remote attackers to execu...
May 2, 2023This CVE describes a critical buffer overflow vulnerability in certain HP LaserJet Pro printers that could allow remote attackers to execute arbitrary...
Apr 28, 2023A buffer overflow vulnerability in the libclinkc.so library of the zhttpd web server on Zyxel DX5401-B0 devices allows remote unauthenticated attacker...
Apr 27, 2023A buffer overflow vulnerability in Netgear R6900, R6700v3, and R6700 routers allows remote attackers to execute arbitrary code or cause denial of serv...
Apr 26, 2023This vulnerability allows remote attackers to execute arbitrary code on affected mobile devices by sending a specially crafted SMS message. It affects...
Apr 13, 2023This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected Qualcomm modem chipsets by exploiting a bu...
Apr 13, 2023CVE-2022-25678 is a critical buffer overflow vulnerability in Qualcomm modem firmware that allows remote code execution. Attackers can exploit this by...
Apr 13, 2023This CVE describes a critical stack-based buffer overflow vulnerability in Rocket Software's UniData and UniVerse database management systems. Attacke...
Mar 29, 2023This CVE describes a critical stack-based buffer overflow vulnerability in Rocket Software's UniData and UniVerse database products. Attackers can exp...
Mar 29, 2023CVE-2020-27507 is a critical buffer overflow vulnerability in Kamailio SIP servers before version 5.5.0. Attackers can crash the server or potentially...
Mar 15, 2023A buffer overflow vulnerability in Pev 0.81 allows arbitrary code execution when processing malicious PE files. The vulnerability occurs due to improp...
Mar 13, 2023This vulnerability in Tenda W15EV1 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a bu...
Mar 13, 2023This vulnerability is a buffer overflow in Tenda W15EV1 routers via the DNSDomainName parameter in the formModifyDnsForward function. Attackers can ex...
Mar 13, 2023A heap buffer overflow vulnerability in ClamAV's HFS+ partition file parser allows remote unauthenticated attackers to execute arbitrary code or cause...
Mar 1, 2023CVE-2021-33226 is a buffer overflow vulnerability in SaltStack's status module that could allow remote code execution. The vulnerability affects SaltS...
Feb 17, 2023This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in...
Feb 12, 2023This vulnerability allows remote attackers to execute arbitrary code on affected IGSS Data Server systems by sending specially crafted messages that t...
Feb 1, 2023This vulnerability in Infiray IRAY-A8Z3 thermal camera firmware allows remote attackers to execute arbitrary code via buffer overflow. Attackers can e...
Jul 17, 2022About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,137 CVEs classified as CWE-120, with 338 rated critical and 629 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free