CWE-120: Buffer Copy without Size Check
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Yearly Trend
Top Affected Vendors
All Buffer Copy without Size Check CVEs (1,146)
This CVE describes a buffer overflow vulnerability in multiple D-Link DSR series routers that allows unauthenticated attackers to execute arbitrary co...
Jan 28, 2025This buffer overflow vulnerability in Edimax AC1200 routers allows attackers to execute arbitrary code by sending specially crafted requests to the /g...
Jan 27, 2025This buffer overflow vulnerability in Edimax AC1200 routers allows attackers to execute arbitrary code by sending specially crafted requests to the we...
Jan 27, 2025IBM Analytics Content Hub 2.0 contains a buffer overflow vulnerability (CWE-120) that allows authenticated remote attackers to execute arbitrary code ...
Jan 25, 2025CVE-2024-53334 is a buffer overflow vulnerability in the infostat.cgi component of TOTOLINK A810R routers. This allows remote attackers to execute arb...
Nov 21, 2024A heap-based buffer overflow vulnerability in tsMuxer allows attackers to execute arbitrary code or cause denial of service by processing a specially ...
Nov 14, 2024A heap-based buffer overflow vulnerability in tsMuxer allows attackers to execute arbitrary code, cause denial of service, or disclose sensitive infor...
Nov 14, 2024A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetPP...
Nov 5, 2024A critical buffer overflow vulnerability in D-Link DIR-619L B1 routers allows remote attackers to execute arbitrary code by manipulating the curTime p...
Oct 13, 2024This critical vulnerability in D-Link DIR-619L B1 routers allows remote attackers to execute arbitrary code via a buffer overflow in the formSetQoS fu...
Oct 13, 2024This critical buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the curTime p...
Oct 13, 2024A critical buffer overflow vulnerability in D-Link DIR-619L B1 router's formSetDDNS function allows remote attackers to execute arbitrary code or cras...
Oct 10, 2024A critical buffer overflow vulnerability in D-Link DIR-619L B1 router's formResetStatistic function allows remote attackers to execute arbitrary code ...
Oct 10, 2024This critical buffer overflow vulnerability in D-Link DIR-619L B1 routers allows remote attackers to execute arbitrary code by manipulating the curTim...
Oct 10, 2024A critical buffer overflow vulnerability in D-Link DIR-619L B1 router firmware allows remote attackers to execute arbitrary code by manipulating the c...
Oct 7, 2024A critical buffer overflow vulnerability in D-Link DIR-619L B1 routers allows remote attackers to execute arbitrary code by manipulating the 'next_pag...
Oct 7, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 7, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the webpage para...
Oct 7, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 6, 2024This critical vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code via a buffer overflow in the web interface's ...
Oct 6, 2024This critical vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code via a buffer overflow in the PPPoE configurat...
Oct 6, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 6, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 6, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 5, 2024This critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the next_page...
Oct 5, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the 'webpage' pa...
Oct 5, 2024A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...
Oct 4, 2024A critical buffer overflow vulnerability in TOTOLINK AC1200 T8 routers allows remote attackers to execute arbitrary code by manipulating the password ...
Sep 8, 2024This critical buffer overflow vulnerability in TOTOLINK AC1200 routers allows remote attackers to execute arbitrary code by sending specially crafted ...
Sep 8, 2024This critical buffer overflow vulnerability in TOTOLINK AC1200 T8 routers allows remote attackers to execute arbitrary code by sending specially craft...
Sep 8, 2024This critical buffer overflow vulnerability in TOTOLINK AC1200 T8 routers allows remote attackers to execute arbitrary code by exploiting the setTrace...
Aug 22, 2024This critical vulnerability in TOTOLINK AC1200 T8 routers allows remote attackers to execute arbitrary code via a buffer overflow in the setDiagnosisC...
Aug 22, 2024A critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the 'current_path' ar...
Aug 16, 2024This critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the 'user' paramet...
Aug 15, 2024A critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the photo_name parame...
Aug 15, 2024A critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the album_name parame...
Aug 15, 2024This critical buffer overflow vulnerability in Tenda i22 routers allows remote attackers to execute arbitrary code by sending specially crafted reques...
Aug 7, 2024A critical buffer overflow vulnerability in Tenda i22 routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...
Aug 7, 2024A critical buffer overflow vulnerability in TOTOLINK CP450 routers allows remote attackers to execute arbitrary code by manipulating the http_host par...
Aug 5, 2024This critical buffer overflow vulnerability in TOTOLINK CP900 routers allows remote attackers to execute arbitrary code by sending specially crafted r...
Aug 5, 2024A critical buffer overflow vulnerability in TOTOLINK EX1200L routers allows remote attackers to execute arbitrary code by manipulating the http_host p...
Aug 1, 2024A critical buffer overflow vulnerability in TOTOLINK N350RT routers allows remote attackers to execute arbitrary code by manipulating time parameters ...
Aug 1, 2024A critical buffer overflow vulnerability in TOTOLINK EX200 routers allows remote attackers to execute arbitrary code by manipulating the http_host par...
Aug 1, 2024This critical vulnerability in TOTOLINK A3300R routers allows remote attackers to execute arbitrary code via a buffer overflow in the UploadCustomModu...
Aug 1, 2024This critical vulnerability in TOTOLINK A7000R routers allows remote attackers to execute arbitrary code via a buffer overflow in the loginauth functi...
Jul 30, 2024This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the UploadCustomModu...
Jul 29, 2024This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the setWebWlanIdx fu...
Jul 29, 2024This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via buffer overflow in the setUrlFilterRules ...
Jul 29, 2024A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the FileName par...
Jul 29, 2024A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the 'comment' pa...
Jul 29, 2024About Buffer Copy without Size Check (CWE-120)
The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Our database tracks 1,146 CVEs classified as CWE-120, with 340 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.
External reference: View CWE-120 on MITRE CWE →
Monitor Buffer Copy without Size Check Vulnerabilities
Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.
Start Monitoring Free