Skip to content
Noroxi

CWE-120 · 3,626 records

Buffer copy without bounds checking

Why does it happen?

When data is copied, the source length is not compared with the size of the destination buffer. Excess data overwrites adjacent memory.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

c
char buf[256];memcpy(buf, pkt->data, pkt->len);

Fixed

c
char buf[256];if (pkt->len > sizeof(buf)) {  return -EINVAL;}memcpy(buf, pkt->data, pkt->len);

How to prevent it

  1. 01Compare the length with the destination size before copying.
  2. 02Take length values from validated bounds, not from data received over the network.
  3. 03Enable compiler protections and prefer memory-safe languages.

CVEs in this class

3,626 records

  • Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · internet information servicesMar 26, 2017

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    netgear · d6100 firmwareJan 30, 2017

  • An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.

    CriticalCVSS 9.8KEVWeaponizedEPSS 82%

    exim · eximFeb 8, 2018

  • Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V,

    HighCVSS 8.8KEVWeaponizedEPSS 88%

    cisco · pix firewall softwareAug 18, 2016

  • A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D

    CriticalCVSS 9.9KEVWeaponizedEPSS 71%

    cisco · adaptive security appliance softwareSep 25, 2025

  • Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with

    HighCVSS 7.8KEVWeaponizedEPSS 87%

    adobe · acrobatFeb 12, 2008

  • D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

    CriticalCVSS 9.8KEVWeaponizedEPSS 56%

    dlink · go-rt-ac750 firmwareAug 28, 2022

  • Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data

    HighCVSS 7.8KEVWeaponizedEPSS 80%

    microsoft · officeJun 11, 2013

  • NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication byp

    CriticalCVSS 9.8KEVWeaponizedEPSS 46%

    netgear · wnr2000 firmwareMay 26, 2017

  • CVE-2010-2572
    79This week

    Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95

    HighCVSS 7.8KEVWeaponizedEPSS 59%

    microsoft · powerpointNov 9, 2010

  • CVE-2006-2492
    79This week

    Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allow

    HighCVSS 8.8KEVWeaponizedEPSS 48%

    microsoft · officeMay 19, 2006

  • CVE-2023-33010
    78This week

    A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri

    CriticalCVSS 9.8KEVWeaponizedEPSS 29%

    zyxel · atp100 firmwareMay 24, 2023

  • CVE-2023-41064
    77This week

    A buffer overflow issue was addressed with improved memory handling.

    HighCVSS 7.8KEVWeaponizedEPSS 53%

    apple · ipadosSep 7, 2023

  • CVE-2023-33009
    77This week

    A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie

    CriticalCVSS 9.8KEVWeaponizedEPSS 28%

    zyxel · atp100 firmwareMay 24, 2023

  • CVE-2020-5135
    77This week

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code

    CriticalCVSS 9.8KEVWeaponizedEPSS 27%

    sonicwall · sonicosOct 12, 2020

  • CVE-2016-0099
    72This week

    The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2

    HighCVSS 7.8KEVWeaponizedEPSS 37%

    microsoft · windows 10 1507Mar 9, 2016

  • CVE-2020-15069
    72This week

    Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles

    CriticalCVSS 9.8KEVWeaponizedEPSS 11%

    sophos · xg firewall firmwareJun 29, 2020

  • CVE-2013-0641
    71This week

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute

    HighCVSS 7.8KEVWeaponizedEPSS 32%

    adobe · acrobatFeb 13, 2013

  • CVE-2011-4862
    68This week

    Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and

    CriticalCVSS 10.0WeaponizedEPSS 95%

    mit · krb5-applDec 24, 2011

  • CVE-2020-11984
    66This week

    Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

    CriticalCVSS 9.8Proof of conceptEPSS 90%

    apache · http serverAug 7, 2020

  • CVE-2021-3711
    65This week

    SM2 Decryption Buffer Overflow

    CriticalCVSS 9.8No exploitEPSS 88%

    openssl · opensslAug 24, 2021

  • CVE-2009-3023
    63This week

    Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to exe

    CriticalCVSS 9.0WeaponizedEPSS 91%

    microsoft · internet information serverAug 31, 2009

  • CVE-2004-0210
    63This week

    The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly b

    HighCVSS 7.8KEVWeaponizedEPSS 7%

    microsoft · interixAug 6, 2004

  • CVE-2020-8012
    62This week

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (c

    CriticalCVSS 9.8WeaponizedEPSS 77%

    broadcom · unified infrastructure managementFeb 18, 2020

All vulnerability classes