CWE-120: Buffer Copy without Size Check

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

1,146
Total CVEs
340
Critical
636
High
8.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
60
2025
251
2024
326
2023
223
2022
94

Top Affected Vendors

1 Qualcomm 82
2 Tenda 59
3 Totolink 52
4 Dlink 52
5 Apple 39
6 Linux 35
7 Netgear 34
8 Debian 31
9 Fedoraproject 27
10 Tp Link 20

All Buffer Copy without Size Check CVEs (1,146)

CVE-2024-7178
8.8

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by sending specially crafted req...

Jul 29, 2024
CVE-2024-7176
8.8

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the setIpQosRules fu...

Jul 29, 2024
CVE-2024-7174
8.8

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by sending specially crafted req...

Jul 29, 2024
CVE-2024-7172
8.8

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the http_host pa...

Jul 28, 2024
CVE-2024-7157
8.8

A critical buffer overflow vulnerability in TOTOLINK A3100R routers allows remote attackers to execute arbitrary code by manipulating the http_host pa...

Jul 28, 2024
CVE-2024-6142
8.8

A buffer overflow vulnerability in the Actiontec WCB6200Q router's HTTP server allows network-adjacent attackers to execute arbitrary code without aut...

Jun 19, 2024
CVE-2023-38581
8.8

A buffer overflow vulnerability in Intel Power Gadget software for Windows allows authenticated local users to potentially escalate privileges. This a...

May 16, 2024
CVE-2024-34196
8.8

This buffer overflow vulnerability in Totolink AC1200 routers allows attackers to execute arbitrary code or cause denial of service by sending special...

May 14, 2024
CVE-2024-4020
8.8

A critical buffer overflow vulnerability in Tenda FH1206 routers allows remote attackers to execute arbitrary code by manipulating the 'entrys' parame...

Apr 20, 2024
CVE-2024-1755
8.8

The NPS computy WordPress plugin through version 2.7.5 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to ...

Apr 15, 2024
CVE-2024-25395
8.8

A buffer overflow vulnerability in RT-Thread's rtlink.c component allows attackers to execute arbitrary code or cause denial of service. This affects ...

Mar 27, 2024
CVE-2015-10123
8.8

This vulnerability allows an unauthenticated attacker to craft malicious packets that trigger a buffer overflow when an authenticated user views them ...

Mar 13, 2024
CVE-2024-24474
8.8

This CVE describes an integer underflow and buffer overflow vulnerability in QEMU's SCSI emulation (esp.c). Attackers can exploit this to execute arbi...

Feb 20, 2024
CVE-2023-40250
8.8

A classic buffer overflow vulnerability in Hancom HCell spreadsheet software allows attackers to execute arbitrary code by sending specially crafted i...

Jan 12, 2024
CVE-2023-42800
8.8

Moonlight-common-c contains a buffer overflow vulnerability in its GameStream client code. A malicious game streaming server could exploit this to cra...

Dec 14, 2023
CVE-2022-34886
8.8

This CVE describes a remote code execution vulnerability in Lenovo printer firmware where an attacker can send a specially crafted string to the serve...

Oct 27, 2023
CVE-2023-44466
8.8

A buffer overflow vulnerability in the Linux kernel's Ceph messenger component allows remote attackers to execute arbitrary code via specially crafted...

Sep 29, 2023
CVE-2023-4582
8.8

This vulnerability allows buffer overflow attacks in Firefox on macOS due to insufficient memory allocation checks in Angle's GLSL shader processing. ...

Sep 11, 2023
CVE-2020-24292
8.8

This is a buffer overflow vulnerability in FreeImage's ICO file parser that allows remote attackers to execute arbitrary code by tricking a user or sy...

Aug 22, 2023
CVE-2020-24295
8.8

CVE-2020-24295 is a buffer overflow vulnerability in FreeImage's PSD parser that allows remote attackers to execute arbitrary code by providing a spec...

Aug 22, 2023
CVE-2023-39550
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Netgear devices via buffer overflows in authentication parameters. At...

Aug 7, 2023
CVE-2023-36499
8.8

This vulnerability allows remote attackers to execute arbitrary code on Netgear XR300 routers via buffer overflows in the wla_ssid and wlg_ssid parame...

Aug 7, 2023
CVE-2023-38591
8.8

This vulnerability allows remote attackers to execute arbitrary code on Netgear DG834Gv5 routers via buffer overflows in the wla_ssid and wla_temp_ssi...

Aug 7, 2023
CVE-2023-38922
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Netgear devices via buffer overflows in authentication parameters. At...

Aug 7, 2023
CVE-2023-38925
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Netgear devices via a buffer overflow in the password.cgi script. Att...

Aug 7, 2023
CVE-2023-3494
8.8

A buffer overflow vulnerability in the fwctl driver of bhyve hypervisor allows malicious privileged software running in a guest VM to execute arbitrar...

Aug 1, 2023
CVE-2023-38590
8.8

This CVE-2023-38590 is a buffer overflow vulnerability in Apple operating systems that allows remote attackers to cause system crashes or corrupt kern...

Jul 28, 2023
CVE-2023-21517
8.8

This is a heap out-of-bounds write vulnerability in Samsung Exynos baseband firmware that allows remote attackers to execute arbitrary code. It affect...

Jun 28, 2023
CVE-2023-25434
8.8

A buffer overflow vulnerability in libtiff's tiffcrop utility allows attackers to execute arbitrary code or cause denial of service by processing spec...

Jun 14, 2023
CVE-2021-33974
8.8

This CVE describes a buffer overflow vulnerability in Qihoo 360 security software that allows remote code execution. Attackers can exploit it by trick...

Apr 19, 2023
CVE-2023-28506
8.8

This CVE describes a stack-based buffer overflow vulnerability in Rocket Software's UniData and UniVerse database products. Attackers with valid login...

Mar 29, 2023
CVE-2022-34756
8.8

This CVE describes a buffer overflow vulnerability in the HTTPS stack of Schneider Electric's Easergy P5 devices, allowing remote attackers to execute...

Jul 13, 2022
CVE-2022-30950
8.8

CVE-2022-30950 is a buffer overflow vulnerability in Jenkins WMI Windows Agents Plugin 1.8 and earlier that allows authenticated users who can connect...

May 17, 2022
CVE-2021-45341
8.8

A buffer overflow vulnerability in LibreCAD's jwwlib component allows remote code execution when processing malicious JWW documents. Attackers can exp...

Jan 25, 2022
CVE-2021-34979
8.8

CVE-2021-34979 is a buffer overflow vulnerability in NETGEAR R6260 routers that allows network-adjacent attackers to execute arbitrary code as root wi...

Jan 13, 2022
CVE-2021-21901
8.8

A stack-based buffer overflow vulnerability in Garrett Metal Detectors' iC Module CMA allows remote attackers to execute arbitrary code by sending spe...

Dec 22, 2021
CVE-2021-42687
8.8

This is a local privilege escalation vulnerability in Accops HyWorks Windows Client where attackers can exploit a buffer overflow in the IOCTL Handler...

Dec 7, 2021
CVE-2021-43637
8.8

This vulnerability is a buffer overflow in the Amazon WorkSpaces agent's IOCTL handler that allows local attackers to execute arbitrary code with kern...

Dec 7, 2021
CVE-2021-42972
8.8

This vulnerability in NoMachine Server allows local attackers to execute arbitrary code with kernel privileges or cause denial of service via memory c...

Dec 7, 2021
CVE-2021-42976
8.8

A buffer overflow vulnerability in NoMachine Enterprise Desktop allows local attackers to execute arbitrary code with kernel privileges or cause denia...

Dec 7, 2021
CVE-2021-42983
8.8

This vulnerability allows local attackers to execute arbitrary code with kernel privileges or cause denial of service via memory corruption in NoMachi...

Dec 7, 2021
CVE-2021-42990
8.8

This vulnerability in FlexiHub for Windows allows local attackers to execute arbitrary code with kernel privileges or crash the operating system throu...

Dec 7, 2021
CVE-2021-42994
8.8

CVE-2021-42994 is a buffer overflow vulnerability in Donglify's IOCTL handler that allows local attackers to execute arbitrary code with kernel privil...

Dec 7, 2021
CVE-2021-43000
8.8

This vulnerability in Amzetta zPortal Windows zClient allows local attackers to execute arbitrary code with kernel privileges or crash the operating s...

Dec 7, 2021
CVE-2020-12140
8.8

This CVE describes a buffer overflow vulnerability in the BLE L2CAP implementation of Contiki-NG, an operating system for IoT devices. Attackers can s...

Dec 7, 2021
CVE-2021-3056
8.8

A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN allows authenticated attackers to execute arbitrary code w...

Nov 10, 2021
CVE-2021-31627
8.8

This CVE describes a buffer overflow vulnerability in Tenda AC9 routers that allows attackers to execute arbitrary code by manipulating the index para...

Oct 29, 2021
CVE-2020-28967
8.8

CVE-2020-28967 is a buffer overflow vulnerability in FlashGet download manager that allows local attackers to execute arbitrary code with elevated pri...

Oct 22, 2021
CVE-2021-38090
8.8

This integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code b...

Sep 20, 2021
CVE-2021-30707
8.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted audio file. It affects Apple devices running macOS, tvOS, watch...

Sep 8, 2021

About Buffer Copy without Size Check (CWE-120)

The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Our database tracks 1,146 CVEs classified as CWE-120, with 340 rated critical and 636 rated high severity. The average CVSS score for Buffer Copy without Size Check vulnerabilities is 8.2.

External reference: View CWE-120 on MITRE CWE →

Monitor Buffer Copy without Size Check Vulnerabilities

Get alerted when new Buffer Copy without Size Check CVEs affect your infrastructure.

Start Monitoring Free