CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,146)
CVE-2021-37778 is a buffer overflow vulnerability in gps-sdr-sim v1.0 that occurs when processing excessively long command line parameters. This allow...
Jun 30, 2022This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the FL...
Jun 14, 2022This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Qualcomm Snapdragon chipsets. I...
Jun 14, 2022A buffer overflow vulnerability in Huawei CV81-WDM firmware allows attackers to execute arbitrary code with elevated privileges. This affects devices ...
Jun 13, 2022CVE-2022-31031 is a critical stack buffer overflow vulnerability in PJSIP's STUN implementation that allows remote code execution. It affects PJSIP us...
Jun 9, 2022CVE-2022-24702 is a critical buffer overflow vulnerability in WinAPRS 2.9.0's VHF KISS TNC component that allows remote code execution via malicious A...
Jun 2, 2022CVE-2022-29246 is a buffer overflow vulnerability in Azure RTOS USBX's DFU UPLOAD functionality that allows attackers to bypass security features or e...
May 24, 2022A buffer overflow vulnerability in the razeraccessory driver of OpenRazer up to v3.3.0 allows attackers to cause a Denial of Service (DoS) and potenti...
May 20, 2022CVE-2022-30055 is a buffer overflow vulnerability in Prime95 version 30.7 build 9 that allows remote attackers to execute arbitrary code on affected s...
May 16, 2022This vulnerability is a buffer overflow in Das U-Boot's NFS client implementation that allows remote code execution. It affects systems using U-Boot w...
May 16, 2022CVE-2022-29591 is a buffer overflow vulnerability in the SetNetControlList function of Tenda TX9 Pro routers running firmware version 22.03.02.10. Thi...
May 10, 2022CVE-2022-28480 is a critical buffer overflow vulnerability in ALLMediaServer 1.6 that allows remote attackers to execute arbitrary code on affected sy...
Apr 29, 2022This is a critical buffer overflow vulnerability in JerryScript's array slice function that allows remote code execution. It affects systems running v...
Apr 5, 2022This CVE describes two buffer overflow vulnerabilities in T10 V2_Firmware's HTTP request parser that allow attackers to execute arbitrary code or cras...
Mar 25, 2022This is a critical buffer overflow vulnerability in Synology DiskStation Manager's authentication functionality that allows remote attackers to execut...
Mar 25, 2022This vulnerability is a buffer overflow in the blocking_request.cgi component of Asus RT-AC68U and RT-AC5300 routers. Attackers can exploit it remotel...
Mar 23, 2022CVE-2022-27240 is a buffer overflow vulnerability in the WebAuthn implementation of Glewlwyd SSO server. Attackers can exploit this to execute arbitra...
Mar 18, 2022This is a critical buffer overflow vulnerability in TP-LINK WR-886N routers that allows remote attackers to execute arbitrary code on affected devices...
Mar 10, 2022A buffer overflow vulnerability in TP-LINK WR-886N routers allows attackers to execute arbitrary code by sending a specially crafted POST request to t...
Mar 10, 2022This CVE describes a critical buffer overflow vulnerability in TP-LINK WR-886N routers, allowing remote attackers to execute arbitrary code via a craf...
Mar 10, 2022This is a critical buffer overflow vulnerability in TP-LINK WR-886N routers that allows remote attackers to execute arbitrary code on affected devices...
Mar 10, 2022A buffer overflow vulnerability in TP-LINK WR-886N routers allows remote attackers to execute arbitrary code via crafted POST requests to the /cloud_c...
Mar 10, 2022This CVE describes a critical buffer overflow vulnerability in Schneider Electric SmartConnect UPS devices that allows remote code execution when proc...
Mar 9, 2022This vulnerability allows remote code execution via a buffer overflow in the PJSUA API's pjsua_call_dump function. Attackers can exploit it by providi...
Feb 16, 2022CVE-2022-24705 is a critical buffer overflow vulnerability in the rad_packet_recv function of accel-ppp's RADIUS packet handling. It allows remote att...
Feb 14, 2022CVE-2021-38172 is a buffer overflow vulnerability in perM 0.4.0 caused by improper use of strncpy. This allows attackers to execute arbitrary code or ...
Feb 5, 2022A buffer overflow vulnerability in Lexmark printer postscript interpreters allows remote code execution. Attackers can exploit this by sending special...
Jan 20, 2022A buffer overflow vulnerability in glibc's sunrpc module allows attackers to execute arbitrary code or cause denial of service. This affects applicati...
Jan 14, 2022CVE-2021-30351 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets, allowing attackers to execute arbitrary code or cause deni...
Jan 3, 2022This vulnerability allows remote attackers to execute arbitrary code on ASUS RT-N53 routers via a buffer overflow in the DNS configuration parameters....
Dec 28, 2021This critical vulnerability allows remote attackers to execute arbitrary code on Garrett Metal Detectors' iC Module CMA systems by sending specially-c...
Dec 22, 2021A buffer overflow vulnerability in SonicWall SMA appliances allows remote unauthenticated attackers to execute arbitrary code as the 'nobody' user. Th...
Dec 8, 2021A buffer overflow vulnerability in the vaultServer component of Kaseya Unitrends Backup Appliance allows remote unauthenticated attackers to execute a...
Dec 6, 2021This CVE describes a critical buffer overflow vulnerability in the SetFirewall function of CIRCUTOR COMPACT DC-S BASIC smart metering concentrators. A...
Dec 2, 2021A buffer overflow vulnerability in TightVNC Viewer allows remote attackers to execute arbitrary code by sending a specially crafted FramebufferUpdate ...
Nov 23, 2021This vulnerability allows remote code execution via buffer overflow in Qualcomm Snapdragon chipsets when processing MBSSID scan information elements. ...
Nov 12, 2021A buffer overflow vulnerability in Broadcom Emulex HBA Manager/One Command Manager allows remote unauthenticated attackers to execute arbitrary code w...
Nov 12, 2021A buffer overflow vulnerability in Realtek RTL8195AM Wi-Fi chips allows remote attackers to execute arbitrary code by sending specially crafted beacon...
Nov 11, 2021This CVE describes a buffer overflow vulnerability in Renleilei1992's Linux_Network_Project version 1.0 that allows attackers to execute arbitrary cod...
Nov 3, 2021This CVE describes a classic buffer overflow vulnerability in Apache Traffic Server's stats-over-http plugin that allows attackers to overwrite memory...
Nov 3, 2021This CVE describes a buffer overflow vulnerability in certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, and HP PageWide Man...
Nov 3, 2021A buffer overflow vulnerability in NEC's Disk Agent component for CLUSTERPRO X and EXPRESSCLUSTER X allows remote attackers to execute arbitrary code ...
Nov 3, 2021A buffer overflow vulnerability in NEC's Transaction Server for CLUSTERPRO X and EXPRESSCLUSTER X allows remote attackers to execute arbitrary code vi...
Nov 3, 2021A buffer overflow vulnerability in NEC's CLUSTERPRO X and EXPRESSCLUSTER X software versions 4.3 and earlier for Windows allows remote attackers to ex...
Nov 3, 2021This vulnerability allows buffer overflow attacks when Go programs compile WebAssembly (WASM) modules with GOARCH=wasm and GOOS=js. Attackers can expl...
Oct 18, 2021A remote buffer overflow vulnerability in HPE Aruba Instant Access Points (IAP) allows unauthenticated attackers to execute arbitrary code or cause de...
Oct 12, 2021A buffer overflow vulnerability in Brandy Basic V Interpreter 1.21 allows attackers to execute arbitrary code by exploiting the run_interpreter functi...
Oct 11, 2021A buffer overflow vulnerability in Miniftpd's do_retr function allows attackers to execute arbitrary code or crash the FTP server. This affects all sy...
Oct 11, 2021This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Digi RealPort for Windows. The buffer o...
Oct 8, 2021This vulnerability allows unauthenticated remote attackers to trigger a buffer overflow in Cisco IOS XE SD-WAN Software by sending crafted traffic. Su...
Sep 23, 2021About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,146 CVEs classified as CWE-120, with 340 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free