CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,146
Total CVEs
117
Critical
840
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Linksys 22

All Buffer Overflow CVEs (1,146)

CVE-2026-2776
10.0

This CVE describes a sandbox escape vulnerability in Firefox's Telemetry component due to incorrect boundary conditions. Attackers could potentially b...

Feb 24, 2026
CVE-2026-2778
10.0

This CVE describes a sandbox escape vulnerability in Firefox's DOM Core & HTML component due to incorrect boundary conditions. It allows malicious web...

Feb 24, 2026
CVE-2024-23613
10.0

A critical buffer overflow vulnerability in Symantec Deployment Solution 7.9 allows remote, unauthenticated attackers to execute arbitrary code with S...

Jan 26, 2024
CVE-2024-23615
10.0

A critical buffer overflow vulnerability in Symantec Messaging Gateway allows remote unauthenticated attackers to execute arbitrary code with root pri...

Jan 26, 2024
CVE-2021-21950
10.0

This critical vulnerability allows remote code execution on Anker Eufy Homebase 2 devices via specially crafted network packets. Attackers can exploit...

Dec 8, 2021
CVE-2026-2788
9.8

This vulnerability involves incorrect boundary conditions in the GMP (Gecko Media Plugins) audio/video component of Firefox, which could allow memory ...

Feb 24, 2026
CVE-2026-2017
9.8

A critical stack-based buffer overflow vulnerability in IP-COM W30AP access points allows remote attackers to execute arbitrary code or crash the devi...

Feb 6, 2026
CVE-2026-1162
9.8

This vulnerability allows remote attackers to execute arbitrary code on UTT HiPER 810 routers by exploiting a buffer overflow in the password change f...

Jan 19, 2026
CVE-2026-0892
9.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Jan 13, 2026
CVE-2026-0879
9.8

This CVE describes a sandbox escape vulnerability in the Graphics component of Mozilla products due to incorrect boundary conditions. Attackers could ...

Jan 13, 2026
CVE-2025-15255
9.8

A remote stack-based buffer overflow vulnerability in Tenda W6-S routers allows attackers to execute arbitrary code by manipulating Cookie parameters ...

Dec 30, 2025
CVE-2025-15194
9.8

A stack-based buffer overflow vulnerability in the hedwig.cgi HTTP header handler of D-Link DIR-600 routers allows remote attackers to execute arbitra...

Dec 29, 2025
CVE-2025-15046
9.8

This is a critical stack-based buffer overflow vulnerability in Tenda WH450 routers that allows remote attackers to execute arbitrary code by sending ...

Dec 23, 2025
CVE-2025-15047
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers by sending specially crafted HTTP requests to the PPTPDCli...

Dec 23, 2025
CVE-2025-15044
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers by exploiting a stack-based buffer overflow in the NatStat...

Dec 23, 2025
CVE-2025-15045
9.8

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Dec 23, 2025
CVE-2025-68615
9.8

A buffer overflow vulnerability in net-snmp's snmptrapd daemon allows remote attackers to crash the service via specially crafted SNMP trap packets. T...

Dec 23, 2025
CVE-2025-15010
9.8

A stack-based buffer overflow vulnerability exists in Tenda WH450 routers version 1.0.0.18, specifically in the /goform/SafeUrlFilter endpoint. Remote...

Dec 22, 2025
CVE-2025-15006
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers by exploiting a stack-based buffer overflow in the HTTP re...

Dec 22, 2025
CVE-2025-15007
9.8

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Dec 22, 2025
CVE-2025-14879
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers by exploiting a stack-based buffer overflow in the HTTP re...

Dec 18, 2025
CVE-2025-14878
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers by exploiting a stack-based buffer overflow in the wireles...

Dec 18, 2025
CVE-2025-14708
9.8

A remote buffer overflow vulnerability exists in Shiguangwu sgwbox N3 devices version 2.0.25 through the WIREDCFGGET interface. Attackers can exploit ...

Dec 15, 2025
CVE-2025-14709
9.8

A buffer overflow vulnerability in the Shiguangwu sgwbox N3 NAS device allows remote attackers to execute arbitrary code by manipulating parameters in...

Dec 15, 2025
CVE-2025-14665
9.8

A remote stack-based buffer overflow vulnerability in Tenda WH450 routers allows attackers to execute arbitrary code by sending specially crafted HTTP...

Dec 14, 2025
CVE-2025-14535
9.8

This is a critical buffer overflow vulnerability in UTT 进取 512W routers that allows remote attackers to execute arbitrary code by exploiting the s...

Dec 11, 2025
CVE-2025-14330
9.8

A JIT (Just-In-Time) compilation vulnerability in the JavaScript engine allows memory corruption when processing malicious JavaScript code. This affec...

Dec 9, 2025
CVE-2025-13188
9.8

A stack-based buffer overflow vulnerability in the authentication.cgi component of D-Link DIR-816L routers allows remote attackers to execute arbitrar...

Nov 14, 2025
CVE-2025-55089
9.8

A buffer overflow vulnerability in FileX's RAM disk driver allows remote attackers to execute arbitrary code by sending specially crafted packets. Thi...

Oct 16, 2025
CVE-2025-11721
9.8

A memory safety vulnerability in Firefox and Thunderbird versions before 144 allows memory corruption that could potentially be exploited to execute a...

Oct 14, 2025
CVE-2025-11423
9.8

This vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code or cause denial of service through memory corruption. Attac...

Oct 8, 2025
CVE-2025-11418
9.8

This is a critical stack-based buffer overflow vulnerability in Tenda CH22 routers that allows remote attackers to execute arbitrary code or crash the...

Oct 8, 2025
CVE-2025-21483
9.8

This vulnerability allows memory corruption when a user equipment (UE) device receives RTP packets during NALU reassembly, potentially leading to remo...

Sep 24, 2025
CVE-2025-10432
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC1206 routers via a stack-based buffer overflow in the HTTP request han...

Sep 15, 2025
CVE-2025-10392
9.8

This vulnerability allows remote attackers to execute arbitrary code on Mercury KM08-708H GiGA WiFi Wave2 routers by sending specially crafted HTTP re...

Sep 14, 2025
CVE-2022-38693
9.8

CVE-2022-38693 is a memory buffer overflow vulnerability in FDL1 (Fastboot Download Layer) due to missing payload size validation. This allows attacke...

Sep 1, 2025
CVE-2022-38696
9.8

CVE-2022-38696 is a critical BootRom vulnerability in Unisoc chipsets where missing payload size checks allow memory buffer overflows. This enables at...

Sep 1, 2025
CVE-2022-38692
9.8

This BootROM vulnerability allows attackers to trigger a memory buffer overflow during RSA key validation without requiring elevated privileges. It af...

Sep 1, 2025
CVE-2025-9605
9.8

A stack-based buffer overflow vulnerability in Tenda AC21 and AC23 routers allows remote attackers to execute arbitrary code by sending specially craf...

Aug 29, 2025
CVE-2025-9523
9.8

This vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the GetParentControl...

Aug 27, 2025
CVE-2025-7775
KEV EPSS 10.6% 9.8

A memory overflow vulnerability in NetScaler ADC and NetScaler Gateway allows remote attackers to execute arbitrary code or cause denial of service. A...

Aug 26, 2025
CVE-2025-9187
9.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Aug 19, 2025
CVE-2025-9179
9.8

This critical memory corruption vulnerability in Mozilla's GMP (Gecko Media Plugin) process allows attackers to potentially execute arbitrary code or ...

Aug 19, 2025
CVE-2025-8760
9.8

A buffer overflow vulnerability in INSTAR IP camera firmware allows remote attackers to execute arbitrary code by sending specially crafted Authorizat...

Aug 13, 2025
CVE-2025-43186
9.8

This is a critical memory corruption vulnerability in Apple's file parsing components across multiple operating systems. Exploitation could allow arbi...

Jul 30, 2025
CVE-2025-7206
9.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-825 router's httpd component allows remote attackers to execute arbitrary code by m...

Jul 9, 2025
CVE-2025-6543
KEV 9.8

A critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway allows attackers to manipulate control flow and cause denial of servic...

Jun 25, 2025
CVE-2025-6121
9.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-632 routers allows remote attackers to execute arbitrary code by sending specially ...

Jun 16, 2025
CVE-2025-47869
9.8

A buffer overflow vulnerability exists in Apache NuttX RTOS's XMLRPC example application due to hardcoded buffer sizes in device stats structures. Thi...

Jun 16, 2025
CVE-2025-6098
9.8

This critical vulnerability in UTT 进取 750W devices allows remote attackers to execute arbitrary code via buffer overflow in the API's password par...

Jun 16, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,146 CVEs classified as CWE-119, with 117 rated critical and 840 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free