CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,146)
A critical buffer overflow vulnerability in Siemens SIPROTEC 5 relays allows attackers to send specially crafted packets to port 4443/tcp, potentially...
Sep 14, 2021This CVE describes a critical buffer overflow vulnerability in Siemens APOGEE and TALON building automation controllers. Unauthenticated remote attack...
Sep 14, 2021This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P searc...
Sep 8, 2021A remote buffer overflow vulnerability in Aruba SD-WAN Software and Gateways allows attackers to execute arbitrary code or cause denial of service. Af...
Sep 7, 2021A heap-based buffer overflow vulnerability in AT&T Labs Xmill 0.7 allows remote code execution when processing malicious XMI files. Attackers can expl...
Aug 20, 2021This heap-based buffer overflow vulnerability in Xmill 0.7's XML decompression allows attackers to execute arbitrary code by providing a malicious fil...
Aug 20, 2021This vulnerability is a buffer overflow in D-Link DIR-615 C2 routers that allows attackers to crash the webserver and potentially execute arbitrary co...
Aug 6, 2021A buffer overflow vulnerability in Swisslog Healthcare Nexus Panel's HMI3 Control Panel allows remote code execution via malformed UDP messages. This ...
Aug 2, 2021A buffer overflow vulnerability in Swisslog Healthcare Nexus Panel's HMI3 Control Panel allows remote attackers to execute arbitrary code by sending s...
Aug 2, 2021This CVE describes a buffer overflow vulnerability in Pillow (Python Imaging Library) that allows attackers to pass controlled parameters to trigger m...
Jul 13, 2021A buffer overflow vulnerability in the jsvGetStringChars function in Espruino firmware allows remote attackers to execute arbitrary code on affected d...
Jul 13, 2021CVE-2021-30475 is a critical buffer overflow vulnerability in libaom's noise_model.c component that allows attackers to execute arbitrary code or caus...
Jun 4, 2021A stack buffer overflow vulnerability in ZeroMQ servers before version 4.3.3 allows malicious clients to execute arbitrary code or crash the server by...
May 28, 2021CVE-2021-31535 is a critical buffer overflow vulnerability in libX11's XLookupColor function that allows remote attackers to execute arbitrary code on...
May 27, 2021This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause denial-of-service via a buffer overflow in the ...
Apr 30, 2021This critical buffer overflow vulnerability in Tenda G1 and G3 routers allows remote attackers to execute arbitrary code by sending a specially crafte...
Apr 14, 2021This critical buffer overflow vulnerability in Tenda G1 and G3 routers allows remote attackers to execute arbitrary code by sending a specially crafte...
Apr 14, 2021CVE-2021-27357 is a buffer overflow vulnerability in RIOT-OS's RPL routing protocol implementation that allows remote attackers to execute arbitrary c...
Apr 6, 2021CVE-2021-27698 is a critical buffer overflow vulnerability in RIOT-OS's RPL routing protocol implementation that allows remote code execution. Attacke...
Apr 6, 2021A buffer overflow vulnerability in Core FTP Server allows remote attackers to execute arbitrary code by sending a specially crafted username. This aff...
Apr 5, 2021A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service. Affected ...
Mar 30, 2021A remote buffer overflow vulnerability in Aruba Instant Access Points allows attackers to execute arbitrary code or cause denial of service by sending...
Mar 30, 2021This is a critical buffer overflow vulnerability in FreeBSD's rtsold IPv6 router advertisement daemon. Attackers can exploit it by sending malicious D...
Mar 29, 2021CVE-2021-3466 is a buffer overflow vulnerability in libmicrohttpd's post_process_urlencoded function due to missing bounds checking. This allows remot...
Mar 25, 2021A buffer overflow vulnerability in Qualcomm Snapdragon video processing allows attackers to execute arbitrary code by playing specially crafted video ...
Mar 17, 2021This vulnerability allows remote attackers to execute arbitrary code on Sagemcom F@ST 3686 v2 routers by sending an overly long sessionKey parameter t...
Jan 26, 2021CVE-2021-3185 is a critical buffer overflow vulnerability in the GStreamer H.264 parser component (gst-plugins-bad). Attackers can exploit this by sen...
Jan 26, 2021CVE-2020-3686 is a buffer overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution during music playback. An attacker ...
Jan 21, 2021CVE-2020-11225 is a buffer overflow vulnerability in Qualcomm WLAN drivers affecting numerous Snapdragon platforms. Attackers can exploit this by send...
Jan 21, 2021This is a buffer overflow vulnerability in Python's ctypes module that could allow remote code execution. It affects Python applications that process ...
Jan 19, 2021CVE-2020-26759 is a critical buffer overflow vulnerability in clickhouse-driver that allows a malicious ClickHouse server to crash client applications...
Jan 6, 2021This vulnerability in the arr crate for Rust allows attackers to trigger buffer overflow conditions through Index and IndexMut operations. It affects ...
Dec 31, 2020This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated at...
Dec 30, 2020CVE-2020-29203 is a critical buffer overflow vulnerability in struct2json library versions before 2020-11-18. Attackers can exploit this vulnerability...
Dec 26, 2020This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Contiki and Contiki-NG operatin...
Dec 11, 2020A buffer overflow vulnerability in Flexense DupScout Enterprise web server allows remote unauthenticated attackers to execute arbitrary code with SYST...
Dec 9, 2020CVE-2020-6017 is a heap-based buffer overflow vulnerability in Valve's Game Networking Sockets library that allows remote attackers to execute arbitra...
Dec 3, 2020CVE-2020-14260 is a critical buffer overflow vulnerability in HCL Domino's DXL component that allows remote code execution. Attackers can exploit impr...
Dec 2, 2020CVE-2020-6018 is a critical stack-based buffer overflow vulnerability in Valve's Game Networking Sockets library when compiled with libsodium. Attacke...
Dec 2, 2020CVE-2020-27745 is a critical buffer overflow vulnerability in Slurm's PMIx MPI plugin that allows remote code execution. Attackers can exploit this by...
Nov 27, 2020CVE-2020-28864 is a buffer overflow vulnerability in WinSCP 5.17.8 that allows a malicious FTP server to trigger a denial of service or potentially ex...
Nov 23, 2020A buffer overflow vulnerability in the TCP/IP function of Mitsubishi Electric GOT 1000 series GT14 model firmware allows remote unauthenticated attack...
Nov 6, 2020A buffer overflow vulnerability in the TCP/IP function of Mitsubishi Electric MELSEC iQ-R series modules allows remote unauthenticated attackers to cr...
Nov 2, 2020This CVE describes a buffer overflow vulnerability in Qualcomm Snapdragon chipsets affecting multiple product lines. Attackers can exploit this by sen...
Nov 2, 2020This CVE describes a buffer overflow vulnerability in macOS that could allow attackers to execute arbitrary code on affected systems. It affects macOS...
Oct 27, 2020CVE-2020-27678 is a buffer overflow vulnerability in the parse_user_name function of libpam in illumos-based operating systems. This allows attackers ...
Oct 26, 2020CVE-2020-5135 is a critical buffer overflow vulnerability in SonicOS firewalls that allows remote attackers to cause denial of service or potentially ...
Oct 12, 2020CVE-2020-26154 is a critical buffer overflow vulnerability in libproxy's url.cpp component when PAC (Proxy Auto-Configuration) is enabled. Attackers c...
Sep 30, 2020A buffer overflow vulnerability in Cesanta Mongoose's mg_get_http_header function allows remote attackers to execute arbitrary code or cause denial of...
Sep 18, 2020A critical buffer overflow vulnerability in PAN-OS allows unauthenticated attackers to send malicious requests to the Captive Portal or Multi-Factor A...
Sep 9, 2020About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,146 CVEs classified as CWE-120, with 340 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free