CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,192
Total CVEs
136
Critical
866
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
168
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,192)

CVE-2023-42881
7.8

This is a memory corruption vulnerability in macOS that could allow an attacker to execute arbitrary code or cause application crashes by processing a...

Jan 23, 2024
CVE-2023-51257
7.8

CVE-2023-51257 is an invalid memory write vulnerability in Jasper-Software Jasper v4.1.1 and earlier that allows local attackers to execute arbitrary ...

Jan 16, 2024
CVE-2022-47965
7.8

This is a macOS kernel memory corruption vulnerability that allows malicious applications to execute arbitrary code with kernel privileges. It affects...

Jan 10, 2024
CVE-2023-39443
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious .lxt2 file in GTKWave. Attackers can craft files that trigger out-of-...

Jan 8, 2024
CVE-2023-38649
7.8

CVE-2023-38649 is an out-of-bounds write vulnerability in GTKWave's VZT file decompression that allows arbitrary code execution when a malicious .vzt ...

Jan 8, 2024
CVE-2023-37447
7.8

CVE-2023-37447 is a memory corruption vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a user opens a malicious .v...

Jan 8, 2024
CVE-2023-37443
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious VCD file in GTKWave. Attackers can exploit out-of-bounds read vulnera...

Jan 8, 2024
CVE-2023-37445
7.8

CVE-2023-37445 is a critical vulnerability in GTKWave 3.3.115 where specially crafted VCD files can trigger out-of-bounds read/write conditions leadin...

Jan 8, 2024
CVE-2023-35970
7.8

CVE-2023-35970 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser that allows arbitrary code execution when a user opens a mal...

Jan 8, 2024
CVE-2023-35958
7.8

CVE-2023-35958 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser that allows arbitrary code execution when a user opens a mal...

Jan 8, 2024
CVE-2023-35956
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious .fst file in GTKWave. Attackers can exploit heap-based buffer overflo...

Jan 8, 2024
CVE-2023-34436
7.8

This CVE describes an out-of-bounds write vulnerability in GTKWave's LXT2 file parser that allows arbitrary code execution when a malicious .lxt2 file...

Jan 8, 2024
CVE-2023-28551
7.8

This vulnerability allows memory corruption in Qualcomm modem UTILS when processing Diag commands with arbitrary address values. Attackers could poten...

Dec 5, 2023
CVE-2023-28587
7.8

This vulnerability allows memory corruption in Qualcomm Bluetooth controllers when parsing specific debug commands at the HCI interface level. Attacke...

Dec 5, 2023
CVE-2023-47580
7.8

This vulnerability involves multiple buffer overflow issues in TELLUS and TELLUS Lite software versions up to V4.0.17.0. Attackers can exploit these f...

Nov 15, 2023
CVE-2023-42841
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Oct 25, 2023
CVE-2023-42856
7.8

This is a memory corruption vulnerability in macOS that could allow arbitrary code execution or application crashes when processing malicious files. I...

Oct 25, 2023
CVE-2023-40423
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an app to execute arbitrary code with kernel privileges. It affects i...

Oct 25, 2023
CVE-2023-42506
7.8

A memory buffer boundary vulnerability in OnSinView2 versions 2.0.1 and earlier allows attackers to execute arbitrary code or disclose information by ...

Oct 17, 2023
CVE-2023-25527
7.8

This vulnerability in NVIDIA DGX H100 BMC's host KVM daemon allows authenticated local attackers to corrupt kernel memory, potentially leading to arbi...

Sep 20, 2023
CVE-2023-41846
7.8

A memory corruption vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious S...

Sep 12, 2023
CVE-2023-28549
7.8

This vulnerability allows memory corruption in Qualcomm's WLAN HAL (Hardware Abstraction Layer) when parsing received network buffers containing TLV (...

Sep 5, 2023
CVE-2023-32270
7.8

This vulnerability in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0 is a memory corruption issue where opening a specially crafted V8 file can cause the ...

Jun 19, 2023
CVE-2023-30986
7.8

A memory corruption vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by tricking users into opening malicious STP files. ...

May 9, 2023
CVE-2022-25713
7.8

CVE-2022-25713 is a memory corruption vulnerability in Qualcomm automotive chipsets that occurs during shared key export operations. Attackers can exp...

May 2, 2023
CVE-2023-1579
7.8

CVE-2023-1579 is a heap-based buffer overflow vulnerability in the bfd_getl64 function of binutils-gdb's Binary File Descriptor (BFD) library. This vu...

Apr 3, 2023
CVE-2023-1676
7.8

This is a critical local privilege escalation vulnerability in DriverGenius software. The vulnerability allows attackers with local access to exploit ...

Mar 28, 2023
CVE-2023-24564
7.8

A memory corruption vulnerability in Solid Edge CAD software allows attackers to execute arbitrary code by tricking users into opening malicious DWG f...

Feb 14, 2023
CVE-2022-41200
7.8

This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious SVG file. Attackers can exploit memor...

Oct 11, 2022
CVE-2022-41196
7.8

This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious VRML file. Attackers can exploit impr...

Oct 11, 2022
CVE-2022-41193
7.8

This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious Encapsulated PostScript (.eps) or AI....

Oct 11, 2022
CVE-2022-41187
7.8

This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious Wavefront Object (.obj) file. Attacke...

Oct 11, 2022
CVE-2022-41185
7.8

This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious Visual Design Stream (.vds) file. Att...

Oct 11, 2022
CVE-2022-41180
7.8

This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious PDF file. Attackers can exploit impro...

Oct 11, 2022
CVE-2022-41177
7.8

This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious IGES file. Attackers can exploit impr...

Oct 11, 2022
CVE-2022-41172
7.8

This vulnerability allows remote code execution when a user opens a malicious AutoCAD DXF file in SAP 3D Visual Enterprise Author. Attackers can explo...

Oct 11, 2022
CVE-2022-39808
7.8

CVE-2022-39808 is a memory corruption vulnerability in SAP 3D Visual Enterprise Author that allows remote code execution when a user opens a malicious...

Oct 11, 2022
CVE-2022-41168
7.8

This vulnerability allows remote code execution when a user opens a malicious CATIA5 Part (.catpart) file in SAP 3D Visual Enterprise Author version 9...

Oct 11, 2022
CVE-2022-39803
7.8

This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious ACIS Part and Assembly (.sat) file. A...

Oct 11, 2022
CVE-2022-39805
7.8

This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious Computer Graphics Metafile (.cgm) fil...

Oct 11, 2022
CVE-2021-26369
7.8

CVE-2021-26369 is an AMD Secure Processor bootloader vulnerability where malicious or compromised UApp/ABL can send malformed system calls, causing ou...

May 12, 2022
CVE-2021-0189
7.8

CVE-2021-0189 is a BIOS firmware vulnerability in certain Intel processors where improper pointer offset validation allows a privileged attacker to es...

May 12, 2022
CVE-2022-1441
7.8

CVE-2022-1441 is a buffer overflow vulnerability in MP4Box (part of GPAC) that occurs when parsing malicious MP4 files. Attackers can exploit this to ...

Apr 25, 2022
CVE-2021-39798
7.8

This vulnerability allows arbitrary code execution through a missing bounds check in Android's Bitmap processing. It affects Android 12 and 12L device...

Apr 12, 2022
CVE-2022-25959
7.8

Omron CX-Position versions 2.5.3 and earlier contain a memory corruption vulnerability when processing specific project files. This allows attackers t...

Apr 1, 2022
CVE-2022-0500
7.8

This vulnerability in the Linux kernel's BPF subsystem allows a local user to trigger an out-of-bounds memory write via the BPF_BTF_LOAD command. This...

Mar 25, 2022
CVE-2022-26125
7.8

CVE-2022-26125 is a buffer overflow vulnerability in FRRouting's IS-IS protocol implementation due to insufficient input validation of packet length. ...

Mar 3, 2022
CVE-2022-26127
7.8

CVE-2022-26127 is a buffer overflow vulnerability in FRRouting's Babel routing protocol daemon that allows remote attackers to execute arbitrary code ...

Mar 3, 2022
CVE-2022-26129
7.8

CVE-2022-26129 is a buffer overflow vulnerability in FRRouting's Babel routing daemon due to improper length validation of sub-TLV fields in Babel pro...

Mar 3, 2022
CVE-2022-22706
7.8

This vulnerability in Arm Mali GPU Kernel Driver allows non-privileged users to write to read-only memory pages, potentially leading to privilege esca...

Mar 3, 2022

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,192 CVEs classified as CWE-119, with 136 rated critical and 866 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free