CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,172
Total CVEs
124
Critical
859
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,172)

CVE-2025-5903
8.8

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted POST r...

Jun 10, 2025
CVE-2025-5905
8.8

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted POST r...

Jun 10, 2025
CVE-2025-5902
8.8

This critical vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code via a buffer overflow in the firmware upgrade fu...

Jun 9, 2025
CVE-2025-5863
8.8

This critical vulnerability in Tenda AC5 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the reboot tim...

Jun 9, 2025
CVE-2025-5862
8.8

A critical buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the PPTP user list fun...

Jun 9, 2025
CVE-2025-5855
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the reboot...

Jun 9, 2025
CVE-2025-5853
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the remote...

Jun 9, 2025
CVE-2025-5851
8.8

A critical buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POS...

Jun 9, 2025
CVE-2025-5849
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially craf...

Jun 8, 2025
CVE-2025-5847
8.8

This critical vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web manage...

Jun 8, 2025
CVE-2025-5839
8.8

A critical buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code by sending specially crafted POST requ...

Jun 7, 2025
CVE-2025-5798
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the timeTy...

Jun 6, 2025
CVE-2025-5794
8.8

A critical buffer overflow vulnerability in Tenda AC5 routers allows remote attackers to execute arbitrary code by manipulating the PPTP user list fun...

Jun 6, 2025
CVE-2025-5792
8.8

A critical buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 6, 2025
CVE-2025-5789
8.8

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request h...

Jun 6, 2025
CVE-2025-5788
8.8

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request h...

Jun 6, 2025
CVE-2025-5786
8.8

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 6, 2025
CVE-2025-5785
8.8

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...

Jun 6, 2025
CVE-2025-5738
8.8

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 6, 2025
CVE-2025-5736
8.8

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 6, 2025
CVE-2025-5734
8.8

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 6, 2025
CVE-2025-5685
8.8

A critical stack-based buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page...

Jun 5, 2025
CVE-2025-5671
8.8

A critical buffer overflow vulnerability in TOTOLINK N302R Plus routers allows remote attackers to execute arbitrary code by sending specially crafted...

Jun 5, 2025
CVE-2025-5629
8.8

A critical buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP req...

Jun 5, 2025
CVE-2025-5619
8.8

A critical stack-based buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the Passw...

Jun 4, 2025
CVE-2025-5608
8.8

A critical buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the rebootTime parame...

Jun 4, 2025
CVE-2025-5572
8.8

A critical stack-based buffer overflow vulnerability in D-Link DCS-932L IP cameras allows remote attackers to execute arbitrary code by manipulating t...

Jun 4, 2025
CVE-2025-5527
8.8

This critical vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the SetStaticR...

Jun 3, 2025
CVE-2025-5503
8.8

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formMap...

Jun 3, 2025
CVE-2025-5215
8.8

A critical stack-based buffer overflow vulnerability in D-Link DCS-5020L IP cameras allows remote attackers to execute arbitrary code by manipulating ...

May 27, 2025
CVE-2025-5156
8.8

A critical buffer overflow vulnerability in H3C GR-5400AX routers allows remote attackers to execute arbitrary code by manipulating the 'param' argume...

May 25, 2025
CVE-2025-24189
8.8

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malic...

May 19, 2025
CVE-2025-4897
8.8

This critical vulnerability in Tenda A15 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request hand...

May 18, 2025
CVE-2025-4843
8.8

A critical stack-based buffer overflow vulnerability in D-Link DCS-932L IP cameras allows remote attackers to execute arbitrary code by sending specia...

May 18, 2025
CVE-2025-4841
8.8

A critical stack-based buffer overflow vulnerability exists in D-Link DCS-932L IP cameras running firmware version 2.18.01. Remote attackers can explo...

May 17, 2025
CVE-2025-4835
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

May 17, 2025
CVE-2025-4834
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

May 17, 2025
CVE-2025-4832
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

May 17, 2025
CVE-2025-4830
8.8

This critical vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handl...

May 17, 2025
CVE-2025-4827
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

May 17, 2025
CVE-2025-4823
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

May 17, 2025
CVE-2025-4825
8.8

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST ...

May 17, 2025
CVE-2025-4810
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the reboot...

May 16, 2025
CVE-2025-4809
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the device...

May 16, 2025
CVE-2025-4733
8.8

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially...

May 16, 2025
CVE-2025-4730
8.8

This critical buffer overflow vulnerability in TOTOLINK A3002R/A3002RU routers allows remote attackers to execute arbitrary code by sending specially ...

May 16, 2025
CVE-2025-31246
8.8

This vulnerability in macOS AFP (Apple Filing Protocol) allows a malicious AFP server to corrupt kernel memory when a vulnerable macOS system connects...

May 12, 2025
CVE-2025-31204
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine affecting multiple Apple operating systems and Safari. Processing malicious...

May 12, 2025
CVE-2025-4496
8.8

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter ...

May 10, 2025
CVE-2025-4462
8.8

A critical buffer overflow vulnerability in TOTOLINK N150RT routers allows remote attackers to execute arbitrary code by manipulating the localPin par...

May 9, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,172 CVEs classified as CWE-119, with 124 rated critical and 859 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free