CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,183
Total CVEs
133
Critical
861
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
163
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,183)

CVE-2023-30431
8.4

This CVE describes a buffer overflow vulnerability in IBM Db2's db2set utility across multiple versions. An attacker could exploit this to execute arb...

Jul 10, 2023
CVE-2023-21628
8.4

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing specific wireless commands. Attackers ...

Jun 6, 2023
CVE-2023-27285
8.4

This buffer overflow vulnerability in IBM Aspera Connect and Cargo allows attackers to execute arbitrary code on affected systems by sending specially...

Jun 5, 2023
CVE-2023-27284
8.4

This CVE describes a buffer overflow vulnerability in IBM Aspera Cargo and Connect 4.2.5 that allows attackers to execute arbitrary code on affected s...

Apr 2, 2023
CVE-2023-45234
8.3

A buffer overflow vulnerability in EDK2's Network Package allows attackers to execute arbitrary code by sending malicious DHCPv6 Advertise messages. T...

Jan 16, 2024
CVE-2023-45230
8.3

EDK2's Network Package has a buffer overflow vulnerability in the DHCPv6 client when processing long server ID options. Attackers on the same network ...

Jan 16, 2024
CVE-2025-58750
8.2

This CVE describes a buffer overflow vulnerability in rAthena MMORPG server software where missing bounds checking in the character slot movement func...

Sep 9, 2025
CVE-2025-4423
8.2

This CVE describes a memory corruption vulnerability in Lenovo products that could allow attackers to execute arbitrary code or cause denial of servic...

Jul 30, 2025
CVE-2025-31234
8.2

This CVE describes a memory corruption vulnerability in Apple operating systems that could allow an attacker to cause system crashes or corrupt kernel...

May 12, 2025
CVE-2024-36129
8.2

CVE-2024-36129 is an unsafe decompression vulnerability in OpenTelemetry Collector that allows unauthenticated attackers to crash the service via exce...

Jun 5, 2024
CVE-2024-1174
8.2

CVE-2024-1174 affects HP ThinPro operating system versions prior to 8.0 SP 8, potentially allowing memory corruption vulnerabilities. This impacts org...

Mar 1, 2024
CVE-2023-5131
8.2

A heap buffer overflow vulnerability in Delta Electronics ISPSoft allows remote code execution when a user opens a malicious DVP file. This affects us...

Jan 18, 2024
CVE-2023-6549
8.2

CVE-2023-6549 is a memory buffer vulnerability in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to cause denial of service...

Jan 17, 2024
CVE-2023-4967
8.2

CVE-2023-4967 is a buffer overflow vulnerability in Citrix NetScaler ADC and Gateway that allows remote attackers to cause denial of service. It affec...

Oct 27, 2023
CVE-2022-24419
8.2

Dell BIOS contains an improper input validation vulnerability in System Management Mode (SMM). A local authenticated attacker can exploit this via Sys...

Mar 11, 2022
CVE-2022-24421
8.2

CVE-2022-24421 is a BIOS vulnerability in Dell systems where improper input validation allows a local authenticated attacker to execute arbitrary code...

Mar 11, 2022
CVE-2022-24415
8.2

This CVE describes an improper input validation vulnerability in Dell BIOS that allows a local authenticated malicious user to exploit System Manageme...

Mar 11, 2022
CVE-2021-41838
8.2

This vulnerability allows attackers to access System Management Mode (SMM) and execute arbitrary code in Insyde InsydeH2O UEFI firmware. It affects sy...

Feb 3, 2022
CVE-2021-33627
8.2

This vulnerability in Insyde InsydeH2O Kernel allows attackers to use invalid buffer addresses with the EFI_SMM_COMMUNICATION_PROTOCOL Communicate() f...

Feb 3, 2022
CVE-2026-0891
8.1

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Jan 13, 2026
CVE-2025-13027
8.1

Memory safety vulnerabilities in Firefox and Thunderbird versions before 145 could allow memory corruption. With sufficient effort, attackers could po...

Nov 11, 2025
CVE-2025-9184
8.1

This CVE describes memory safety vulnerabilities in Firefox and Thunderbird that could allow memory corruption. With sufficient effort, attackers coul...

Aug 19, 2025
CVE-2025-5268
8.1

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

May 27, 2025
CVE-2025-4091
8.1

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Apr 29, 2025
CVE-2025-4093
8.1

A memory safety vulnerability in Firefox ESR and Thunderbird could allow attackers to execute arbitrary code on affected systems. This affects Firefox...

Apr 29, 2025
CVE-2024-8938
8.1

A buffer overflow vulnerability in Schneider Electric products allows remote code execution via crafted Modbus packets. Attackers can exploit this thr...

Nov 13, 2024
CVE-2024-22373
8.1

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a specially crafted DICOM file containing malforme...

Apr 25, 2024
CVE-2023-4234
8.1

CVE-2023-4234 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. Attackers can exploit this via SMS...

Apr 17, 2024
CVE-2023-4232
8.1

CVE-2023-4232 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. Attackers can exploit this via SMS...

Apr 17, 2024
CVE-2024-3865
8.1

CVE-2024-3865 is a memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulnerability ...

Apr 16, 2024
CVE-2023-2794
8.1

CVE-2023-2794 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. It affects Linux systems using ofo...

Apr 10, 2024
CVE-2023-32284
8.1

CVE-2023-32284 is an out-of-bounds write vulnerability in Accusoft ImageGear's TIFF processing functionality that allows memory corruption via special...

Sep 25, 2023
CVE-2021-1451
8.1

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on Cisco Catalyst 4500 series switches runni...

Mar 24, 2021
CVE-2025-52264
8.0

This vulnerability allows remote attackers to execute arbitrary code on StarCharge Artemis AC Chargers by exploiting a stack overflow in the download....

Oct 27, 2025
CVE-2025-12235
8.0

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows attackers on the local network to execute arbitrary code by manip...

Oct 27, 2025
CVE-2025-5869
8.0

A critical memory corruption vulnerability exists in RT-Thread's sys_recvfrom function, allowing attackers to execute arbitrary code or cause denial o...

Jun 9, 2025
CVE-2025-5868
8.0

This critical vulnerability in RT-Thread 5.1.0 allows improper array index validation in the sys_thread_sigprocmask function, potentially enabling mem...

Jun 9, 2025
CVE-2025-5865
8.0

CVE-2025-5865 is a critical memory corruption vulnerability in RT-Thread 5.1.0's sys_select function. Attackers can exploit improper timeout parameter...

Jun 9, 2025
CVE-2025-31223
8.0

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malic...

May 12, 2025
CVE-2025-4446
8.0

A critical buffer overflow vulnerability in H3C GR-5400AX routers allows attackers to execute arbitrary code by manipulating the param argument in the...

May 9, 2025
CVE-2025-4440
8.0

A critical buffer overflow vulnerability in H3C GR-1800AX routers allows attackers to execute arbitrary code by manipulating the EnableIpv6 function's...

May 8, 2025
CVE-2025-2851
8.0

A critical buffer overflow vulnerability in the RPC handler component of GL.iNet routers allows attackers to execute arbitrary code or crash devices. ...

Apr 26, 2025
CVE-2025-3854
8.0

A critical buffer overflow vulnerability in H3C GR-3000AX routers allows attackers to execute arbitrary code or crash the device by sending specially ...

Apr 22, 2025
CVE-2023-52434
8.0

This CVE-2023-52434 is an out-of-bounds read vulnerability in the Linux kernel's SMB client implementation. It allows attackers to trigger kernel cras...

Feb 20, 2024
CVE-2021-4157
8.0

This vulnerability is an out-of-bounds memory write flaw in the Linux kernel's NFS subsystem, specifically affecting mirroring/replication functionali...

Mar 25, 2022
CVE-2021-38473
8.0

This vulnerability allows attackers to trigger a stack overflow by manipulating function arguments in affected products, potentially leading to arbitr...

Oct 22, 2021
CVE-2023-48267
7.9

This vulnerability in Intel System Security Report and System Resources Defense firmware allows privileged users to bypass buffer restrictions, potent...

Feb 12, 2025
CVE-2024-21980
7.9

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to improperly write to a guest's protected memory regions....

Aug 5, 2024
CVE-2026-20700
KEV 7.8

A memory corruption vulnerability in Apple operating systems allows attackers with memory write capability to execute arbitrary code. This affects wat...

Feb 11, 2026
CVE-2026-25634
7.8

This CVE describes a buffer overlap vulnerability in iccDEV's CIccTagMultiProcessElement::Apply() function where SrcPixel and DestPixel stack buffers ...

Feb 6, 2026

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,183 CVEs classified as CWE-119, with 133 rated critical and 861 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free