CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,189
Total CVEs
135
Critical
864
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
166
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,189)

CVE-2024-11610
7.8

This vulnerability allows remote attackers to execute arbitrary code on AutomationDirect C-More EA9 programming software installations. Attackers can ...

Jan 30, 2025
CVE-2024-11611
7.8

This vulnerability allows remote attackers to execute arbitrary code on AutomationDirect C-More EA9 programming software installations by tricking use...

Jan 30, 2025
CVE-2025-0412
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot Viewer installations by tricking users into opening malicious K...

Jan 13, 2025
CVE-2024-43049
7.8

This vulnerability allows local attackers to cause memory corruption in WLAN drivers by sending specially crafted IOCTL calls. It affects devices usin...

Dec 2, 2024
CVE-2024-43053
7.8

This vulnerability allows memory corruption when user-space applications make IOCTL calls to read WLAN diagnostic information. Attackers could potenti...

Dec 2, 2024
CVE-2024-9739
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-9731
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. At...

Nov 22, 2024
CVE-2024-8815
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U...

Nov 22, 2024
CVE-2024-11573
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11575
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11553
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The memory corru...

Nov 22, 2024
CVE-2024-11557
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11547
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView when users open malicious DWG...

Nov 22, 2024
CVE-2024-11551
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The memory corru...

Nov 22, 2024
CVE-2024-11539
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ac...

Nov 22, 2024
CVE-2024-11541
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11543
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11527
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DWG files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11519
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious RLE files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11523
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit this b...

Nov 22, 2024
CVE-2024-8600
7.8

A memory corruption vulnerability in Autodesk AutoCAD allows attackers to execute arbitrary code by tricking users into opening malicious SLDPRT files...

Oct 29, 2024
CVE-2024-9489
7.8

This vulnerability allows attackers to exploit a memory corruption flaw in AutoCAD by tricking users into opening malicious DWG files. Successful expl...

Oct 29, 2024
CVE-2024-8598
7.8

A memory corruption vulnerability in Autodesk AutoCAD's ACTranslators.exe allows attackers to execute arbitrary code by tricking users into opening ma...

Oct 29, 2024
CVE-2024-47046
7.8

A memory corruption vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious BDF files. Th...

Oct 8, 2024
CVE-2024-45474
7.8

This vulnerability allows memory corruption when parsing specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulati...

Oct 8, 2024
CVE-2024-45472
7.8

This vulnerability allows memory corruption when parsing malicious WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation softw...

Oct 8, 2024
CVE-2024-45468
7.8

This vulnerability allows remote code execution through memory corruption when parsing malicious WRL files in Siemens Teamcenter Visualization and Tec...

Oct 8, 2024
CVE-2024-23355
7.8

This vulnerability allows memory corruption in Qualcomm's keymaster component when importing shared keys, potentially leading to arbitrary code execut...

Aug 5, 2024
CVE-2024-0153
7.8

This CVE describes a memory buffer overflow vulnerability in Arm's Valhall and 5th Gen GPU firmware that allows a local non-privileged user to perform...

Jul 1, 2024
CVE-2024-27857
7.8

This CVE describes an out-of-bounds memory access vulnerability in multiple Apple operating systems that could allow a remote attacker to crash applic...

Jun 10, 2024
CVE-2024-5306
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Kofax Power PDF by tricking users into ...

Jun 6, 2024
CVE-2023-52548
7.8

This vulnerability allows a malicious OS attacker to corrupt arbitrary SMRAM memory through the SMI handler in Huawei Matebook D16's ThisiServicesSmm ...

May 28, 2024
CVE-2023-51608
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K files in Kofax Power PDF. Attackers ...

May 3, 2024
CVE-2023-42078
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-42047
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in PDF-XChange Editor. The fla...

May 3, 2024
CVE-2023-42036
7.8

This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw e...

May 3, 2024
CVE-2023-37333
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PCX files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2022-48655
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's SCMI (System Control and Management Interface) reset domains sub...

Apr 28, 2024
CVE-2022-48662
7.8

A use-after-free vulnerability in the Linux kernel's i915 graphics driver allows local attackers to cause a kernel panic (denial of service) or potent...

Apr 28, 2024
CVE-2024-26884
7.8

A vulnerability in the Linux kernel's BPF subsystem allows integer overflow during hashtable bucket calculation on 32-bit architectures. This can lead...

Apr 17, 2024
CVE-2024-27344
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Kofax Power PDF. The flaw e...

Apr 3, 2024
CVE-2024-26599
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's PWM (Pulse Width Modulation) subsystem. When args->args_count eq...

Feb 23, 2024
CVE-2023-52464
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's EDAC driver for ThunderX processors. The bug occurs when strncat() is incorre...

Feb 23, 2024
CVE-2023-52444
7.8

A directory entry corruption vulnerability in the Linux kernel's F2FS filesystem allows attackers to corrupt directory structures during rename operat...

Feb 22, 2024
CVE-2024-26588
7.8

A memory access vulnerability in the Linux kernel's BPF JIT compiler for LoongArch architecture allows out-of-bounds memory access when processing lar...

Feb 22, 2024
CVE-2023-52440
7.8

A buffer overflow vulnerability in the Linux kernel's ksmbd component allows attackers to overflow session key buffers during NTLMSSP authentication. ...

Feb 21, 2024
CVE-2021-46757
7.8

This AMD Secure Processor vulnerability allows a malicious Trusted Application (TA) to read from or write to the ASP Secure OS kernel virtual address ...

Feb 13, 2024
CVE-2024-24921
7.8

A memory corruption vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious Catia MODEL f...

Feb 13, 2024
CVE-2023-42881
7.8

This is a memory corruption vulnerability in macOS that could allow an attacker to execute arbitrary code or cause application crashes by processing a...

Jan 23, 2024
CVE-2023-51257
7.8

CVE-2023-51257 is an invalid memory write vulnerability in Jasper-Software Jasper v4.1.1 and earlier that allows local attackers to execute arbitrary ...

Jan 16, 2024

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,189 CVEs classified as CWE-119, with 135 rated critical and 864 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free