CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,187
Total CVEs
134
Critical
863
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
165
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,187)

CVE-2026-20700
KEV 7.8

A memory corruption vulnerability in Apple operating systems allows attackers with memory write capability to execute arbitrary code. This affects wat...

Feb 11, 2026
CVE-2026-25634
7.8

This CVE describes a buffer overlap vulnerability in iccDEV's CIccTagMultiProcessElement::Apply() function where SrcPixel and DestPixel stack buffers ...

Feb 6, 2026
CVE-2026-25585
7.8

This vulnerability in iccDEV allows attackers to trigger an out-of-bounds read by providing a malformed ICC color profile. This can lead to memory dis...

Feb 4, 2026
CVE-2026-25582
7.8

A heap buffer overflow vulnerability in iccDEV's CIccIO::WriteUInt16Float() function allows attackers to cause denial of service or potentially execut...

Feb 4, 2026
CVE-2026-25583
7.8

A heap buffer overflow vulnerability exists in iccDEV's CIccFileIO::Read8() function when processing malformed ICC profile files. This allows attacker...

Feb 4, 2026
CVE-2026-25584
7.8

A stack-buffer-overflow vulnerability in iccDEV's CIccTagFloatNum::GetValues() function allows memory corruption when processing malformed ICC color p...

Feb 4, 2026
CVE-2026-1260
7.8

CVE-2026-1260 is an invalid memory access vulnerability in Sentencepiece versions before 0.2.1 that occurs when processing specially crafted model fil...

Jan 22, 2026
CVE-2024-44238
7.8

This vulnerability allows malicious apps to corrupt coprocessor memory on Apple iOS and iPadOS devices. It affects users running iOS/iPadOS versions b...

Jan 16, 2026
CVE-2025-12771
7.8

CVE-2025-12771 is a stack-based buffer overflow vulnerability in IBM Concert versions 1.0.0 through 2.1.0. A local authenticated user could exploit th...

Dec 26, 2025
CVE-2025-14419
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect by tricking user...

Dec 23, 2025
CVE-2025-5555
7.8

A stack-based buffer overflow vulnerability exists in the Nixdorf Wincor PORT IO Driver's IOCTL handler (wnport.sys). This allows local attackers to e...

Oct 18, 2025
CVE-2025-43277
7.8

This memory corruption vulnerability in macOS audio file processing allows attackers to execute arbitrary code or cause denial of service by tricking ...

Jul 30, 2025
CVE-2025-7316
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7318
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7320
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7308
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7310
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7314
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7302
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7304
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7306
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running IrfanView with the CADImage plugin when users open malicious D...

Jul 21, 2025
CVE-2025-7294
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7296
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7300
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7288
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7290
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7292
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7280
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7282
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7284
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7286
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7274
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7276
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7278
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7266
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7270
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7272
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7257
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7253
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7255
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7244
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7249
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7236
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7240
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-6693
7.8

A critical memory corruption vulnerability in RT-Thread's device driver functions allows local attackers to potentially execute arbitrary code or cras...

Jun 26, 2025
CVE-2025-1246
7.8

A memory buffer overflow vulnerability in Arm GPU drivers allows non-privileged user processes to access memory outside allocated bounds via GPU opera...

Jun 2, 2025
CVE-2025-25175
7.8

A memory corruption vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious .NEU files. T...

Mar 13, 2025
CVE-2025-26597
7.8

A buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service by exploiting improper mem...

Feb 25, 2025
CVE-2024-11610
7.8

This vulnerability allows remote attackers to execute arbitrary code on AutomationDirect C-More EA9 programming software installations. Attackers can ...

Jan 30, 2025
CVE-2024-11611
7.8

This vulnerability allows remote attackers to execute arbitrary code on AutomationDirect C-More EA9 programming software installations by tricking use...

Jan 30, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,187 CVEs classified as CWE-119, with 134 rated critical and 863 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free