CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,146
Total CVEs
340
Critical
636
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 82
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,146)

CVE-2021-33719
9.8

A critical buffer overflow vulnerability in Siemens SIPROTEC 5 relays allows attackers to send specially crafted packets to port 4443/tcp, potentially...

Sep 14, 2021
CVE-2021-27391
9.8

This CVE describes a critical buffer overflow vulnerability in Siemens APOGEE and TALON building automation controllers. Unauthenticated remote attack...

Sep 14, 2021
CVE-2021-1972
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P searc...

Sep 8, 2021
CVE-2021-37716
9.8

A remote buffer overflow vulnerability in Aruba SD-WAN Software and Gateways allows attackers to execute arbitrary code or cause denial of service. Af...

Sep 7, 2021
CVE-2021-21826
9.8

A heap-based buffer overflow vulnerability in AT&T Labs Xmill 0.7 allows remote code execution when processing malicious XMI files. Attackers can expl...

Aug 20, 2021
CVE-2021-21828
9.8

This heap-based buffer overflow vulnerability in Xmill 0.7's XML decompression allows attackers to execute arbitrary code by providing a malicious fil...

Aug 20, 2021
CVE-2021-37388
9.8

This vulnerability is a buffer overflow in D-Link DIR-615 C2 routers that allows attackers to crash the webserver and potentially execute arbitrary co...

Aug 6, 2021
CVE-2021-37162
9.8

A buffer overflow vulnerability in Swisslog Healthcare Nexus Panel's HMI3 Control Panel allows remote code execution via malformed UDP messages. This ...

Aug 2, 2021
CVE-2021-37165
9.8

A buffer overflow vulnerability in Swisslog Healthcare Nexus Panel's HMI3 Control Panel allows remote attackers to execute arbitrary code by sending s...

Aug 2, 2021
CVE-2021-34552
9.8

This CVE describes a buffer overflow vulnerability in Pillow (Python Imaging Library) that allows attackers to pass controlled parameters to trigger m...

Jul 13, 2021
CVE-2020-22884
9.8

A buffer overflow vulnerability in the jsvGetStringChars function in Espruino firmware allows remote attackers to execute arbitrary code on affected d...

Jul 13, 2021
CVE-2021-30475
9.8

CVE-2021-30475 is a critical buffer overflow vulnerability in libaom's noise_model.c component that allows attackers to execute arbitrary code or caus...

Jun 4, 2021
CVE-2021-20236
9.8

A stack buffer overflow vulnerability in ZeroMQ servers before version 4.3.3 allows malicious clients to execute arbitrary code or crash the server by...

May 28, 2021
CVE-2021-31535
9.8

CVE-2021-31535 is a critical buffer overflow vulnerability in libX11's XLookupColor function that allows remote attackers to execute arbitrary code on...

May 27, 2021
CVE-2020-24918
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause denial-of-service via a buffer overflow in the ...

Apr 30, 2021
CVE-2021-27707
9.8

This critical buffer overflow vulnerability in Tenda G1 and G3 routers allows remote attackers to execute arbitrary code by sending a specially crafte...

Apr 14, 2021
CVE-2021-27705
9.8

This critical buffer overflow vulnerability in Tenda G1 and G3 routers allows remote attackers to execute arbitrary code by sending a specially crafte...

Apr 14, 2021
CVE-2021-27357
9.8

CVE-2021-27357 is a buffer overflow vulnerability in RIOT-OS's RPL routing protocol implementation that allows remote attackers to execute arbitrary c...

Apr 6, 2021
CVE-2021-27698
9.8

CVE-2021-27698 is a critical buffer overflow vulnerability in RIOT-OS's RPL routing protocol implementation that allows remote code execution. Attacke...

Apr 6, 2021
CVE-2020-19596
9.8

A buffer overflow vulnerability in Core FTP Server allows remote attackers to execute arbitrary code by sending a specially crafted username. This aff...

Apr 5, 2021
CVE-2019-5319
9.8

A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service. Affected ...

Mar 30, 2021
CVE-2021-25149
9.8

A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service by sending...

Mar 30, 2021
CVE-2020-25583
9.8

This is a critical buffer overflow vulnerability in FreeBSD's rtsold IPv6 router advertisement daemon. Attackers can exploit it by sending malicious D...

Mar 29, 2021
CVE-2021-3466
9.8

CVE-2021-3466 is a buffer overflow vulnerability in libmicrohttpd's post_process_urlencoded function due to missing bounds checking. This allows remot...

Mar 25, 2021
CVE-2020-11299
9.8

A buffer overflow vulnerability in Qualcomm Snapdragon video processing allows attackers to execute arbitrary code by playing specially crafted video ...

Mar 17, 2021
CVE-2021-3304
9.8

This vulnerability allows remote attackers to execute arbitrary code on Sagemcom F@ST 3686 v2 routers by sending an overly long sessionKey parameter t...

Jan 26, 2021
CVE-2021-3185
9.8

CVE-2021-3185 is a critical buffer overflow vulnerability in the GStreamer H.264 parser component (gst-plugins-bad). Attackers can exploit this by sen...

Jan 26, 2021
CVE-2020-3686
9.8

CVE-2020-3686 is a buffer overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution during music playback. An attacker ...

Jan 21, 2021
CVE-2020-11225
9.8

CVE-2020-11225 is a buffer overflow vulnerability in Qualcomm WLAN drivers affecting numerous Snapdragon platforms. Attackers can exploit this by send...

Jan 21, 2021
CVE-2021-3177
9.8

This is a buffer overflow vulnerability in Python's ctypes module that could allow remote code execution. It affects Python applications that process ...

Jan 19, 2021
CVE-2020-26759
9.8

CVE-2020-26759 is a critical buffer overflow vulnerability in clickhouse-driver that allows a malicious ClickHouse server to crash client applications...

Jan 6, 2021
CVE-2020-35887
9.8

This vulnerability in the arr crate for Rust allows attackers to trigger buffer overflow conditions through Index and IndexMut operations. It affects ...

Dec 31, 2020
CVE-2020-35795
9.8

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated at...

Dec 30, 2020
CVE-2020-29203
9.8

CVE-2020-29203 is a critical buffer overflow vulnerability in struct2json library versions before 2020-11-18. Attackers can exploit this vulnerability...

Dec 26, 2020
CVE-2020-24336
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Contiki and Contiki-NG operatin...

Dec 11, 2020
CVE-2020-29659
9.8

A buffer overflow vulnerability in Flexense DupScout Enterprise web server allows remote unauthenticated attackers to execute arbitrary code with SYST...

Dec 9, 2020
CVE-2020-6017
9.8

CVE-2020-6017 is a heap-based buffer overflow vulnerability in Valve's Game Networking Sockets library that allows remote attackers to execute arbitra...

Dec 3, 2020
CVE-2020-14260
9.8

CVE-2020-14260 is a critical buffer overflow vulnerability in HCL Domino's DXL component that allows remote code execution. Attackers can exploit impr...

Dec 2, 2020
CVE-2020-6018
9.8

CVE-2020-6018 is a critical stack-based buffer overflow vulnerability in Valve's Game Networking Sockets library when compiled with libsodium. Attacke...

Dec 2, 2020
CVE-2020-27745
9.8

CVE-2020-27745 is a critical buffer overflow vulnerability in Slurm's PMIx MPI plugin that allows remote code execution. Attackers can exploit this by...

Nov 27, 2020
CVE-2020-28864
9.8

CVE-2020-28864 is a buffer overflow vulnerability in WinSCP 5.17.8 that allows a malicious FTP server to trigger a denial of service or potentially ex...

Nov 23, 2020
CVE-2020-5644
9.8

A buffer overflow vulnerability in the TCP/IP function of Mitsubishi Electric GOT 1000 series GT14 model firmware allows remote unauthenticated attack...

Nov 6, 2020
CVE-2020-5653
9.8

A buffer overflow vulnerability in the TCP/IP function of Mitsubishi Electric MELSEC iQ-R series modules allows remote unauthenticated attackers to cr...

Nov 2, 2020
CVE-2020-3692
9.8

This CVE describes a buffer overflow vulnerability in Qualcomm Snapdragon chipsets affecting multiple product lines. Attackers can exploit this by sen...

Nov 2, 2020
CVE-2020-9866
9.8

This CVE describes a buffer overflow vulnerability in macOS that could allow attackers to execute arbitrary code on affected systems. It affects macOS...

Oct 27, 2020
CVE-2020-27678
9.8

CVE-2020-27678 is a buffer overflow vulnerability in the parse_user_name function of libpam in illumos-based operating systems. This allows attackers ...

Oct 26, 2020
CVE-2020-5135
9.8

CVE-2020-5135 is a critical buffer overflow vulnerability in SonicOS firewalls that allows remote attackers to cause denial of service or potentially ...

Oct 12, 2020
CVE-2020-26154
9.8

CVE-2020-26154 is a critical buffer overflow vulnerability in libproxy's url.cpp component when PAC (Proxy Auto-Configuration) is enabled. Attackers c...

Sep 30, 2020
CVE-2020-25756
9.8

A buffer overflow vulnerability in Cesanta Mongoose's mg_get_http_header function allows remote attackers to execute arbitrary code or cause denial of...

Sep 18, 2020
CVE-2020-2040
9.8

A critical buffer overflow vulnerability in PAN-OS allows unauthenticated attackers to send malicious requests to the Captive Portal or Multi-Factor A...

Sep 9, 2020

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,146 CVEs classified as CWE-120, with 340 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free