CWE-119: Buffer Overflow
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Yearly Trend
Top Affected Vendors
All Buffer Overflow CVEs (1,192)
This is a memory corruption vulnerability in macOS that could allow an attacker to execute arbitrary code or cause application crashes by processing a...
Jan 23, 2024CVE-2023-51257 is an invalid memory write vulnerability in Jasper-Software Jasper v4.1.1 and earlier that allows local attackers to execute arbitrary ...
Jan 16, 2024This is a macOS kernel memory corruption vulnerability that allows malicious applications to execute arbitrary code with kernel privileges. It affects...
Jan 10, 2024This vulnerability allows arbitrary code execution when a user opens a malicious .lxt2 file in GTKWave. Attackers can craft files that trigger out-of-...
Jan 8, 2024CVE-2023-38649 is an out-of-bounds write vulnerability in GTKWave's VZT file decompression that allows arbitrary code execution when a malicious .vzt ...
Jan 8, 2024CVE-2023-37447 is a memory corruption vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a user opens a malicious .v...
Jan 8, 2024This vulnerability allows arbitrary code execution when a user opens a malicious VCD file in GTKWave. Attackers can exploit out-of-bounds read vulnera...
Jan 8, 2024CVE-2023-37445 is a critical vulnerability in GTKWave 3.3.115 where specially crafted VCD files can trigger out-of-bounds read/write conditions leadin...
Jan 8, 2024CVE-2023-35970 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser that allows arbitrary code execution when a user opens a mal...
Jan 8, 2024CVE-2023-35958 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser that allows arbitrary code execution when a user opens a mal...
Jan 8, 2024This vulnerability allows arbitrary code execution when a user opens a malicious .fst file in GTKWave. Attackers can exploit heap-based buffer overflo...
Jan 8, 2024This CVE describes an out-of-bounds write vulnerability in GTKWave's LXT2 file parser that allows arbitrary code execution when a malicious .lxt2 file...
Jan 8, 2024This vulnerability allows memory corruption in Qualcomm modem UTILS when processing Diag commands with arbitrary address values. Attackers could poten...
Dec 5, 2023This vulnerability allows memory corruption in Qualcomm Bluetooth controllers when parsing specific debug commands at the HCI interface level. Attacke...
Dec 5, 2023This vulnerability involves multiple buffer overflow issues in TELLUS and TELLUS Lite software versions up to V4.0.17.0. Attackers can exploit these f...
Nov 15, 2023This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...
Oct 25, 2023This is a memory corruption vulnerability in macOS that could allow arbitrary code execution or application crashes when processing malicious files. I...
Oct 25, 2023This is a memory corruption vulnerability in Apple operating systems that allows an app to execute arbitrary code with kernel privileges. It affects i...
Oct 25, 2023A memory buffer boundary vulnerability in OnSinView2 versions 2.0.1 and earlier allows attackers to execute arbitrary code or disclose information by ...
Oct 17, 2023This vulnerability in NVIDIA DGX H100 BMC's host KVM daemon allows authenticated local attackers to corrupt kernel memory, potentially leading to arbi...
Sep 20, 2023A memory corruption vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious S...
Sep 12, 2023This vulnerability allows memory corruption in Qualcomm's WLAN HAL (Hardware Abstraction Layer) when parsing received network buffers containing TLV (...
Sep 5, 2023This vulnerability in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0 is a memory corruption issue where opening a specially crafted V8 file can cause the ...
Jun 19, 2023A memory corruption vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by tricking users into opening malicious STP files. ...
May 9, 2023CVE-2022-25713 is a memory corruption vulnerability in Qualcomm automotive chipsets that occurs during shared key export operations. Attackers can exp...
May 2, 2023CVE-2023-1579 is a heap-based buffer overflow vulnerability in the bfd_getl64 function of binutils-gdb's Binary File Descriptor (BFD) library. This vu...
Apr 3, 2023This is a critical local privilege escalation vulnerability in DriverGenius software. The vulnerability allows attackers with local access to exploit ...
Mar 28, 2023A memory corruption vulnerability in Solid Edge CAD software allows attackers to execute arbitrary code by tricking users into opening malicious DWG f...
Feb 14, 2023This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious SVG file. Attackers can exploit memor...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious VRML file. Attackers can exploit impr...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious Encapsulated PostScript (.eps) or AI....
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Viewer allows remote code execution when a user opens a malicious Wavefront Object (.obj) file. Attacke...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious Visual Design Stream (.vds) file. Att...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious PDF file. Attackers can exploit impro...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious IGES file. Attackers can exploit impr...
Oct 11, 2022This vulnerability allows remote code execution when a user opens a malicious AutoCAD DXF file in SAP 3D Visual Enterprise Author. Attackers can explo...
Oct 11, 2022CVE-2022-39808 is a memory corruption vulnerability in SAP 3D Visual Enterprise Author that allows remote code execution when a user opens a malicious...
Oct 11, 2022This vulnerability allows remote code execution when a user opens a malicious CATIA5 Part (.catpart) file in SAP 3D Visual Enterprise Author version 9...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious ACIS Part and Assembly (.sat) file. A...
Oct 11, 2022This vulnerability in SAP 3D Visual Enterprise Author allows remote code execution when a user opens a malicious Computer Graphics Metafile (.cgm) fil...
Oct 11, 2022CVE-2021-26369 is an AMD Secure Processor bootloader vulnerability where malicious or compromised UApp/ABL can send malformed system calls, causing ou...
May 12, 2022CVE-2021-0189 is a BIOS firmware vulnerability in certain Intel processors where improper pointer offset validation allows a privileged attacker to es...
May 12, 2022CVE-2022-1441 is a buffer overflow vulnerability in MP4Box (part of GPAC) that occurs when parsing malicious MP4 files. Attackers can exploit this to ...
Apr 25, 2022This vulnerability allows arbitrary code execution through a missing bounds check in Android's Bitmap processing. It affects Android 12 and 12L device...
Apr 12, 2022Omron CX-Position versions 2.5.3 and earlier contain a memory corruption vulnerability when processing specific project files. This allows attackers t...
Apr 1, 2022This vulnerability in the Linux kernel's BPF subsystem allows a local user to trigger an out-of-bounds memory write via the BPF_BTF_LOAD command. This...
Mar 25, 2022CVE-2022-26125 is a buffer overflow vulnerability in FRRouting's IS-IS protocol implementation due to insufficient input validation of packet length. ...
Mar 3, 2022CVE-2022-26127 is a buffer overflow vulnerability in FRRouting's Babel routing protocol daemon that allows remote attackers to execute arbitrary code ...
Mar 3, 2022CVE-2022-26129 is a buffer overflow vulnerability in FRRouting's Babel routing daemon due to improper length validation of sub-TLV fields in Babel pro...
Mar 3, 2022This vulnerability in Arm Mali GPU Kernel Driver allows non-privileged users to write to read-only memory pages, potentially leading to privilege esca...
Mar 3, 2022About Buffer Overflow (CWE-119)
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Our database tracks 1,192 CVEs classified as CWE-119, with 136 rated critical and 866 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-119 on MITRE CWE →
Monitor Buffer Overflow Vulnerabilities
Get alerted when new Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free