CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,172
Total CVEs
124
Critical
859
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,172)

CVE-2025-4449
8.8

A critical buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the wan_connecte...

May 9, 2025
CVE-2025-4451
8.8

A critical buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...

May 9, 2025
CVE-2025-4442
8.8

A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...

May 9, 2025
CVE-2025-4356
8.8

A critical stack-based buffer overflow vulnerability in Tenda DAP-1520 routers allows remote attackers to execute arbitrary code by sending specially ...

May 6, 2025
CVE-2025-4354
8.8

A critical stack-based buffer overflow vulnerability in Tenda DAP-1520 routers allows remote attackers to execute arbitrary code by manipulating the c...

May 6, 2025
CVE-2025-4347
8.8

A critical buffer overflow vulnerability in D-Link DIR-600L routers allows remote attackers to execute arbitrary code by manipulating the 'host' param...

May 6, 2025
CVE-2025-4345
8.8

A critical buffer overflow vulnerability in D-Link DIR-600L routers allows remote attackers to execute arbitrary code by manipulating the 'host' param...

May 6, 2025
CVE-2025-4342
8.8

A critical buffer overflow vulnerability in D-Link DIR-600L routers allows remote attackers to execute arbitrary code by manipulating the 'host' param...

May 6, 2025
CVE-2025-4299
8.8

A critical buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by exploiting the setSchedWifi func...

May 6, 2025
CVE-2025-4150
8.8

A critical buffer overflow vulnerability in Netgear EX6200 routers allows remote attackers to execute arbitrary code by manipulating the 'host' argume...

May 1, 2025
CVE-2025-4148
8.8

A critical buffer overflow vulnerability in Netgear EX6200 routers allows remote attackers to execute arbitrary code by manipulating the 'host' argume...

May 1, 2025
CVE-2025-4146
8.8

A critical buffer overflow vulnerability in Netgear EX6200 routers allows remote attackers to execute arbitrary code by manipulating the host argument...

May 1, 2025
CVE-2025-4142
8.8

A critical buffer overflow vulnerability in Netgear EX6200 wireless extenders allows remote attackers to execute arbitrary code by manipulating the 'h...

Apr 30, 2025
CVE-2025-4140
8.8

A critical buffer overflow vulnerability in Netgear EX6120 WiFi extender firmware allows remote attackers to execute arbitrary code or crash the devic...

Apr 30, 2025
CVE-2025-4139
8.8

A critical buffer overflow vulnerability in Netgear EX6120's fwAcosCgiInbound function allows remote attackers to execute arbitrary code by manipulati...

Apr 30, 2025
CVE-2025-4120
8.8

A critical buffer overflow vulnerability in Netgear JWNR2000v2 routers allows remote attackers to execute arbitrary code by manipulating the 'host' ar...

Apr 30, 2025
CVE-2025-4116
8.8

A critical buffer overflow vulnerability in Netgear JWNR2000v2 routers allows remote attackers to execute arbitrary code by manipulating the host argu...

Apr 30, 2025
CVE-2025-4114
8.8

A critical buffer overflow vulnerability in Netgear JWNR2000v2 routers allows remote attackers to execute arbitrary code by manipulating the host argu...

Apr 30, 2025
CVE-2025-3993
8.8

A critical buffer overflow vulnerability in TOTOLINK N150RT routers allows remote attackers to execute arbitrary code by manipulating the submit-url p...

Apr 28, 2025
CVE-2025-3991
8.8

This critical buffer overflow vulnerability in TOTOLINK N150RT routers allows remote attackers to execute arbitrary code by manipulating the submit-ur...

Apr 28, 2025
CVE-2025-3989
8.8

A critical buffer overflow vulnerability in TOTOLINK N150RT routers allows remote attackers to execute arbitrary code by manipulating the Hostname par...

Apr 27, 2025
CVE-2025-3988
8.8

A critical buffer overflow vulnerability in TOTOLINK N150RT routers allows remote attackers to execute arbitrary code by manipulating the service_type...

Apr 27, 2025
CVE-2025-3820
8.8

A critical stack-based buffer overflow vulnerability in Tenda W12 and i24 routers allows remote attackers to execute arbitrary code by manipulating ho...

Apr 19, 2025
CVE-2025-3802
8.8

A critical stack-based buffer overflow vulnerability in Tenda W12 and i24 routers allows remote attackers to execute arbitrary code by manipulating th...

Apr 19, 2025
CVE-2025-3785
8.8

This critical vulnerability in D-Link DWR-M961 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the auth...

Apr 18, 2025
CVE-2025-3693
8.8

This critical vulnerability in Tenda W12 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the cgiWifiRad...

Apr 16, 2025
CVE-2025-3328
8.8

A critical buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by manipulating the ssid or timeZon...

Apr 7, 2025
CVE-2025-3259
8.8

A critical stack-based buffer overflow vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code by sending specially craft...

Apr 4, 2025
CVE-2025-3161
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the 'list...

Apr 3, 2025
CVE-2025-2370
8.8

A critical stack-based buffer overflow vulnerability in TOTOLINK EX1800T WiFi extenders allows remote attackers to execute arbitrary code by sending s...

Mar 17, 2025
CVE-2025-2369
8.8

A critical stack-based buffer overflow vulnerability in TOTOLINK EX1800T routers allows remote attackers to execute arbitrary code by manipulating the...

Mar 17, 2025
CVE-2025-1853
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the 'list'...

Mar 3, 2025
CVE-2025-1851
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the firewa...

Mar 3, 2025
CVE-2025-1814
8.8

This critical vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the /goform/Wi...

Mar 2, 2025
CVE-2025-1538
8.8

A critical heap-based buffer overflow vulnerability in D-Link DAP-1320's set_ws_action function allows remote attackers to execute arbitrary code or c...

Feb 21, 2025
CVE-2025-1539
8.8

A critical stack-based buffer overflow vulnerability exists in D-Link DAP-1320 firmware version 1.00, specifically in the replace_special_char functio...

Feb 21, 2025
CVE-2025-1340
8.8

A critical stack-based buffer overflow vulnerability in TOTOLINK X18 routers allows remote attackers to execute arbitrary code by sending specially cr...

Feb 16, 2025
CVE-2025-0566
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'mac'...

Jan 19, 2025
CVE-2025-0349
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the src/ma...

Jan 9, 2025
CVE-2024-11960
8.8

A critical buffer overflow vulnerability in D-Link DIR-605L routers allows remote attackers to execute arbitrary code by manipulating the curTime para...

Nov 28, 2024
CVE-2024-11248
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the reboo...

Nov 15, 2024
CVE-2024-11061
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the timeZ...

Nov 11, 2024
CVE-2024-11056
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the wpaps...

Nov 10, 2024
CVE-2024-11047
8.8

This critical vulnerability in D-Link DI-8003 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the upgra...

Nov 10, 2024
CVE-2024-9396
8.8

A memory corruption vulnerability in Firefox, Firefox ESR, and Thunderbird could allow attackers to execute arbitrary code or cause denial of service ...

Oct 1, 2024
CVE-2024-8573
8.8

A critical buffer overflow vulnerability in TOTOLINK AC1200 routers allows remote attackers to execute arbitrary code by manipulating parameters in th...

Sep 8, 2024
CVE-2024-27851
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine, allowing arbitrary code execution when processing malicious web content. I...

Jun 10, 2024
CVE-2024-27820
8.8

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code on affected devi...

Jun 10, 2024
CVE-2024-3832
8.8

This vulnerability in Chrome's V8 JavaScript engine allows remote attackers to corrupt memory objects via malicious HTML pages, potentially leading to...

Apr 17, 2024
CVE-2024-3159
8.8

This vulnerability allows remote attackers to perform arbitrary memory read/write operations through a crafted HTML page due to out-of-bounds memory a...

Apr 6, 2024

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,172 CVEs classified as CWE-119, with 124 rated critical and 859 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free