CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,176
Total CVEs
126
Critical
861
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
163
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,176)

CVE-2024-27851
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine, allowing arbitrary code execution when processing malicious web content. I...

Jun 10, 2024
CVE-2024-27820
8.8

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code on affected devi...

Jun 10, 2024
CVE-2024-3832
8.8

This vulnerability in Chrome's V8 JavaScript engine allows remote attackers to corrupt memory objects via malicious HTML pages, potentially leading to...

Apr 17, 2024
CVE-2024-3159
8.8

This vulnerability allows remote attackers to perform arbitrary memory read/write operations through a crafted HTML page due to out-of-bounds memory a...

Apr 6, 2024
CVE-2023-43821
8.8

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft allows remote code execution when users open malicious DPS files. Attackers c...

Jan 18, 2024
CVE-2023-43823
8.8

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft allows remote code execution when a user opens a malicious DPS file. This aff...

Jan 18, 2024
CVE-2023-43819
8.8

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft allows remote code execution when a user opens a malicious DPS file. This aff...

Jan 18, 2024
CVE-2023-28410
8.8

This vulnerability in Intel i915 Graphics drivers for Linux allows an authenticated local user to perform memory buffer operations beyond intended bou...

May 10, 2023
CVE-2019-8720
8.8

CVE-2019-8720 is a memory corruption vulnerability in WebKit that allows arbitrary code execution when processing malicious web content. This affects ...

Mar 6, 2023
CVE-2022-0204
8.8

CVE-2022-0204 is a heap overflow vulnerability in BlueZ Bluetooth stack versions before 5.63. An attacker on the local network can send specially craf...

Mar 10, 2022
CVE-2021-43083
8.8

This vulnerability in Apache PLC4X's C implementation (PLC4C) allows unsigned integer underflow in the TCP transport layer. Attackers could exploit th...

Dec 19, 2021
CVE-2021-21898
8.8

This vulnerability allows remote code execution through a specially crafted DWG file in LibreCAD's libdxfrw library. Attackers can exploit an out-of-b...

Nov 19, 2021
CVE-2021-34856
8.8

This vulnerability in Parallels Desktop allows local attackers with high-privileged code execution on a guest system to escalate privileges to hypervi...

Oct 25, 2021
CVE-2021-34859
8.8

CVE-2021-34859 is a remote code execution vulnerability in TeamViewer 15.16.8.0 that allows attackers to execute arbitrary code by tricking users into...

Oct 25, 2021
CVE-2021-3570
8.8

A buffer overflow vulnerability in the ptp4l program of the linuxptp package allows remote attackers to leak information, crash systems, or potentiall...

Jul 9, 2021
CVE-2020-11256
8.8

CVE-2020-11256 is a memory corruption vulnerability in Qualcomm Snapdragon chipsets where improper validation of pointers passed to the TrustZone secu...

Jun 9, 2021
CVE-2020-11258
8.8

This vulnerability allows memory corruption in Qualcomm Snapdragon TrustZone due to insufficient pointer validation. Attackers could potentially execu...

Jun 9, 2021
CVE-2021-30530
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory access in Chrome's WebAudio component via a crafted HTML page. Attackers co...

Jun 7, 2021
CVE-2020-25690
8.8

CVE-2020-25690 is a heap-based out-of-bounds write vulnerability in FontForge that allows attackers to crash applications or execute arbitrary code by...

Feb 23, 2021
CVE-2020-13561
8.8

An out-of-bounds write vulnerability in the TIFF parser of Accusoft ImageGear 19.8 allows remote code execution via specially crafted TIFF files. This...

Feb 10, 2021
CVE-2021-21453
8.8

CVE-2021-21453 is a vulnerability in SAP 3D Visual Enterprise Viewer version 9 that allows attackers to crash the application by tricking users into o...

Jan 12, 2021
CVE-2021-21457
8.8

CVE-2021-21457 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing I...

Jan 12, 2021
CVE-2021-21449
8.8

CVE-2021-21449 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing I...

Jan 12, 2021
CVE-2021-21451
8.8

CVE-2021-21451 is a vulnerability in SAP 3D Visual Enterprise Viewer version 9 that allows attackers to crash the application by tricking users into o...

Jan 12, 2021
CVE-2017-5225
8.8

CVE-2017-5225 is a heap buffer overflow vulnerability in LibTIFF's tiffcp tool that allows attackers to cause denial of service or potentially execute...

Jan 12, 2017
CVE-2025-2521
8.6

This CVE describes a memory buffer vulnerability in Honeywell Experion PKS and OneWireless WDM's Control Data Access component. An attacker could expl...

Jul 10, 2025
CVE-2025-52566
8.6

A signed vs. unsigned integer overflow vulnerability in llama.cpp's tokenizer allows heap overflow when processing manipulated text input during token...

Jun 24, 2025
CVE-2024-21916
8.6

A denial-of-service vulnerability in Rockwell Automation ControlLogix and GuardLogix controllers allows attackers to cause a major nonrecoverable faul...

Jan 31, 2024
CVE-2023-3471
8.6

A buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 allows attackers to execute arbitrary code on affected systems. Thi...

Sep 6, 2023
CVE-2023-3036
8.6

A buffer overflow vulnerability in Cloudflare's cfnts NTP server allows remote attackers to trigger a denial-of-service panic by sending specially cra...

Jun 14, 2023
CVE-2021-34781
8.6

This vulnerability in Cisco Firepower Threat Defense (FTD) Software allows unauthenticated remote attackers to cause denial of service by flooding SSH...

Oct 27, 2021
CVE-2021-31977
8.6

This vulnerability in Windows Hyper-V allows an authenticated attacker on a guest virtual machine to send specially crafted requests to the host, caus...

Jun 8, 2021
CVE-2021-20988
8.6

This vulnerability in Hilscher rcX RTOS allows attackers to send malformed UDP packets where the actual packet length doesn't match the length indicat...

May 13, 2021
CVE-2021-1402
8.6

An unauthenticated remote attacker can send crafted SSL/TLS messages through Cisco Firepower Threat Defense devices performing software-based SSL decr...

Apr 29, 2021
CVE-2021-1241
8.6

Multiple vulnerabilities in Cisco SD-WAN products allow unauthenticated remote attackers to execute denial-of-service attacks against affected devices...

Jan 20, 2021
CVE-2021-1279
8.6

Multiple vulnerabilities in Cisco SD-WAN products allow unauthenticated remote attackers to execute denial-of-service (DoS) attacks against affected d...

Jan 20, 2021
CVE-2021-1274
8.6

Multiple vulnerabilities in Cisco SD-WAN products allow unauthenticated remote attackers to execute denial-of-service attacks against affected devices...

Jan 20, 2021
CVE-2024-52333
8.4

An improper array index validation vulnerability in OFFIS DCMTK's determineMinMax function allows out-of-bounds writes when processing specially craft...

Jan 13, 2025
CVE-2024-47796
8.4

An improper array index validation vulnerability in OFFIS DCMTK's nowindow functionality allows out-of-bounds writes when processing specially crafted...

Jan 13, 2025
CVE-2024-44067
8.4

GhostWrite is a hardware vulnerability in T-Head XuanTie C910 and C920 CPUs that allows unprivileged attackers to write to arbitrary physical memory l...

Aug 19, 2024
CVE-2023-43554
8.4

This vulnerability allows memory corruption through improper input validation in FastRPC's IOCTL handler. Attackers could potentially execute arbitrar...

Jul 1, 2024
CVE-2024-37676
8.4

CVE-2024-37676 is a memory corruption vulnerability in htop-dev htop version 2.20 that allows local attackers to trigger out-of-bounds memory access. ...

Jun 20, 2024
CVE-2023-45168
8.4

This vulnerability allows a non-privileged local user on IBM AIX and VIOS systems to exploit the invscout command to execute arbitrary commands with e...

Dec 1, 2023
CVE-2023-30431
8.4

This CVE describes a buffer overflow vulnerability in IBM Db2's db2set utility across multiple versions. An attacker could exploit this to execute arb...

Jul 10, 2023
CVE-2023-21628
8.4

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing specific wireless commands. Attackers ...

Jun 6, 2023
CVE-2023-27285
8.4

This buffer overflow vulnerability in IBM Aspera Connect and Cargo allows attackers to execute arbitrary code on affected systems by sending specially...

Jun 5, 2023
CVE-2023-27284
8.4

This CVE describes a buffer overflow vulnerability in IBM Aspera Cargo and Connect 4.2.5 that allows attackers to execute arbitrary code on affected s...

Apr 2, 2023
CVE-2023-45234
8.3

A buffer overflow vulnerability in EDK2's Network Package allows attackers to execute arbitrary code by sending malicious DHCPv6 Advertise messages. T...

Jan 16, 2024
CVE-2023-45230
8.3

EDK2's Network Package has a buffer overflow vulnerability in the DHCPv6 client when processing long server ID options. Attackers on the same network ...

Jan 16, 2024
CVE-2025-58750
8.2

This CVE describes a buffer overflow vulnerability in rAthena MMORPG server software where missing bounds checking in the character slot movement func...

Sep 9, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,176 CVEs classified as CWE-119, with 126 rated critical and 861 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free