CWE-120 · 3,626 records
Buffer copy without bounds checking
Why does it happen?
When data is copied, the source length is not compared with the size of the destination buffer. Excess data overwrites adjacent memory.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
char buf[256];memcpy(buf, pkt->data, pkt->len);Fixed
char buf[256];if (pkt->len > sizeof(buf)) { return -EINVAL;}memcpy(buf, pkt->data, pkt->len);How to prevent it
- 01Compare the length with the destination size before copying.
- 02Take length values from validated bounds, not from data received over the network.
- 03Enable compiler protections and prefer memory-safe languages.
CVEs in this class
3,626 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2017-7269Weaponized | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Smicrosoft · internet information services · CWE-120 | Critical9.8 | KEV | 99.8% | Mar 26, 2017 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
94Now | CVE-2016-10174Weaponized | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.netgear · d6100 firmware · CWE-120 | Critical9.8 | KEV | 83.3% | Jan 30, 2017 |
94Now | CVE-2018-6789Weaponized | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Critical9.8 | KEV | 82.1% | Feb 8, 2018 |
91Now | CVE-2016-6366Weaponized | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,cisco · pix firewall software · CWE-120 | High8.8 | KEV | 87.6% | Aug 18, 2016 |
90Now | CVE-2025-20333Weaponized | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Dcisco · adaptive security appliance software · CWE-120 | Critical9.9 | KEV | 70.7% | Sep 25, 2025 |
87Now | CVE-2007-5659Weaponized | Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file withadobe · acrobat · CWE-120 | High7.8 | KEV | 87.4% | Feb 12, 2008 |
86Now | CVE-2022-37055Weaponized | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,dlink · go-rt-ac750 firmware · CWE-120 | Critical9.8 | KEV | 55.5% | Aug 28, 2022 |
85Now | CVE-2013-1331Weaponized | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data microsoft · office · CWE-120 | High7.8 | KEV | 79.8% | Jun 11, 2013 |
83Now | CVE-2017-6862Weaponized | NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypnetgear · wnr2000 firmware · CWE-120 | Critical9.8 | KEV | 45.7% | May 26, 2017 |
79This week | CVE-2010-2572Weaponized | Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 microsoft · powerpoint · CWE-120 | High7.8 | KEV | 58.6% | Nov 9, 2010 |
79This week | CVE-2006-2492Weaponized | Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allowmicrosoft · office · CWE-120 | High8.8 | KEV | 48.1% | May 19, 2006 |
78This week | CVE-2023-33010Weaponized | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX serizyxel · atp100 firmware · CWE-120 | Critical9.8 | KEV | 28.8% | May 24, 2023 |
77This week | CVE-2023-41064Weaponized | A buffer overflow issue was addressed with improved memory handling.apple · ipados · CWE-120 | High7.8 | KEV | 53.4% | Sep 7, 2023 |
77This week | CVE-2023-33009Weaponized | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX seriezyxel · atp100 firmware · CWE-120 | Critical9.8 | KEV | 28.1% | May 24, 2023 |
77This week | CVE-2020-5135Weaponized | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code sonicwall · sonicos · CWE-120 | Critical9.8 | KEV | 26.9% | Oct 12, 2020 |
72This week | CVE-2016-0099Weaponized | The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2microsoft · windows 10 1507 · CWE-120 | High7.8 | KEV | 37.0% | Mar 9, 2016 |
72This week | CVE-2020-15069Weaponized | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlessophos · xg firewall firmware · CWE-120 | Critical9.8 | KEV | 10.7% | Jun 29, 2020 |
71This week | CVE-2013-0641Weaponized | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to executeadobe · acrobat · CWE-120 | High7.8 | KEV | 32.3% | Feb 13, 2013 |
68This week | CVE-2011-4862Weaponized | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Critical10.0 | — | 95.0% | Dec 24, 2011 |
66This week | CVE-2020-11984Proof of concept | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCEapache · http server · CWE-120 | Critical9.8 | — | 90.0% | Aug 7, 2020 |
65This week | CVE-2021-3711No exploit | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Critical9.8 | — | 87.8% | Aug 24, 2021 |
63This week | CVE-2009-3023Weaponized | Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to exemicrosoft · internet information server · CWE-120 | Critical9.0 | — | 90.9% | Aug 31, 2009 |
63This week | CVE-2004-0210Weaponized | The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly bmicrosoft · interix · CWE-120 | High7.8 | KEV | 7.2% | Aug 6, 2004 |
62This week | CVE-2020-8012Weaponized | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (cbroadcom · unified infrastructure management · CWE-120 | Critical9.8 | — | 77.4% | Feb 18, 2020 |
- CVE-2017-726999Now
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · internet information servicesMar 26, 2017
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2016-1017494Now
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.
CriticalCVSS 9.8KEVWeaponizedEPSS 83%netgear · d6100 firmwareJan 30, 2017
- CVE-2018-678994Now
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
CriticalCVSS 9.8KEVWeaponizedEPSS 82%exim · eximFeb 8, 2018
- CVE-2016-636691Now
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,
HighCVSS 8.8KEVWeaponizedEPSS 88%cisco · pix firewall softwareAug 18, 2016
- CVE-2025-2033390Now
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
CriticalCVSS 9.9KEVWeaponizedEPSS 71%cisco · adaptive security appliance softwareSep 25, 2025
- CVE-2007-565987Now
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with
HighCVSS 7.8KEVWeaponizedEPSS 87%adobe · acrobatFeb 12, 2008
- CVE-2022-3705586Now
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
CriticalCVSS 9.8KEVWeaponizedEPSS 56%dlink · go-rt-ac750 firmwareAug 28, 2022
- CVE-2013-133185Now
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data
HighCVSS 7.8KEVWeaponizedEPSS 80%microsoft · officeJun 11, 2013
- CVE-2017-686283Now
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication byp
CriticalCVSS 9.8KEVWeaponizedEPSS 46%netgear · wnr2000 firmwareMay 26, 2017
- CVE-2010-257279This week
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95
HighCVSS 7.8KEVWeaponizedEPSS 59%microsoft · powerpointNov 9, 2010
- CVE-2006-249279This week
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allow
HighCVSS 8.8KEVWeaponizedEPSS 48%microsoft · officeMay 19, 2006
- CVE-2023-3301078This week
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri
CriticalCVSS 9.8KEVWeaponizedEPSS 29%zyxel · atp100 firmwareMay 24, 2023
- CVE-2023-4106477This week
A buffer overflow issue was addressed with improved memory handling.
HighCVSS 7.8KEVWeaponizedEPSS 53%apple · ipadosSep 7, 2023
- CVE-2023-3300977This week
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie
CriticalCVSS 9.8KEVWeaponizedEPSS 28%zyxel · atp100 firmwareMay 24, 2023
- CVE-2020-513577This week
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code
CriticalCVSS 9.8KEVWeaponizedEPSS 27%sonicwall · sonicosOct 12, 2020
- CVE-2016-009972This week
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2
HighCVSS 7.8KEVWeaponizedEPSS 37%microsoft · windows 10 1507Mar 9, 2016
- CVE-2020-1506972This week
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles
CriticalCVSS 9.8KEVWeaponizedEPSS 11%sophos · xg firewall firmwareJun 29, 2020
- CVE-2013-064171This week
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute
HighCVSS 7.8KEVWeaponizedEPSS 32%adobe · acrobatFeb 13, 2013
- CVE-2011-486268This week
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
CriticalCVSS 10.0WeaponizedEPSS 95%mit · krb5-applDec 24, 2011
- CVE-2020-1198466This week
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
CriticalCVSS 9.8Proof of conceptEPSS 90%apache · http serverAug 7, 2020
- CVE-2021-371165This week
SM2 Decryption Buffer Overflow
CriticalCVSS 9.8No exploitEPSS 88%openssl · opensslAug 24, 2021
- CVE-2009-302363This week
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to exe
CriticalCVSS 9.0WeaponizedEPSS 91%microsoft · internet information serverAug 31, 2009
- CVE-2004-021063This week
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly b
HighCVSS 7.8KEVWeaponizedEPSS 7%microsoft · interixAug 6, 2004
- CVE-2020-801262This week
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (c
CriticalCVSS 9.8WeaponizedEPSS 77%broadcom · unified infrastructure managementFeb 18, 2020