CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,195
Total CVEs
136
Critical
869
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
169
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,195)

CVE-2022-22706
7.8

This vulnerability in Arm Mali GPU Kernel Driver allows non-privileged users to write to read-only memory pages, potentially leading to privilege esca...

Mar 3, 2022
CVE-2021-46153
7.8

This vulnerability allows remote code execution through memory corruption when Simcenter Femap parses malicious NEU files. Attackers can execute arbit...

Feb 9, 2022
CVE-2021-46157
7.8

This vulnerability allows remote code execution through memory corruption when Simcenter Femap parses malicious NEU files. Attackers could execute arb...

Feb 9, 2022
CVE-2021-34874
7.8

CVE-2021-34874 is a memory corruption vulnerability in Bentley View that allows remote code execution when processing malicious 3DS files. Attackers c...

Jan 13, 2022
CVE-2021-30289
7.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service via buffer overflow in Qualcomm Snapdragon chipsets. It affec...

Jan 3, 2022
CVE-2021-33481
7.8

CVE-2021-33481 is a stack-based buffer overflow vulnerability in gocr (optical character recognition software) that allows attackers to execute arbitr...

Nov 17, 2021
CVE-2021-33479
7.8

A stack-based buffer overflow vulnerability exists in gocr's measure_pitch() function in pgm2asc.c. This allows attackers to execute arbitrary code or...

Nov 17, 2021
CVE-2021-38436
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting memory corruption in FATEK Automation WinProladder when parsing malicious ...

Oct 18, 2021
CVE-2021-38442
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious project files in FATEK Automation WinProladder....

Oct 18, 2021
CVE-2021-1816
7.8

This CVE describes a buffer overflow vulnerability in Apple's iOS, iPadOS, watchOS, and tvOS that allows malicious applications to execute arbitrary c...

Sep 8, 2021
CVE-2021-31979
7.8

This is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. It...

Jul 14, 2021
CVE-2021-1502
7.8

This vulnerability allows remote code execution through malicious Webex recording files (ARF/WRF formats). An attacker can send a malicious file via e...

Jun 4, 2021
CVE-2021-1526
7.8

CVE-2021-1526 is a remote code execution vulnerability in Cisco Webex Player for Windows and macOS. Attackers can exploit it by tricking users into op...

Jun 4, 2021
CVE-2021-30499
7.8

CVE-2021-30499 is a buffer overflow vulnerability in libcaca's export_troff function that could allow memory corruption. This affects systems using li...

May 27, 2021
CVE-2021-30472
7.8

CVE-2021-30472 is a stack-based buffer overflow vulnerability in PoDoFo, a PDF manipulation library, due to improper validation of key length in the e...

May 26, 2021
CVE-2021-22543
7.8

This CVE-2021-22543 vulnerability in Linux KVM allows attackers with VM control privileges to bypass read-only memory checks, potentially leading to m...

May 26, 2021
CVE-2021-27397
7.8

This vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by exploiting memory corruption when parsing malicious SP...

May 12, 2021
CVE-2020-11288
7.8

CVE-2020-11288 is an out-of-bounds write vulnerability in Qualcomm's PlayReady DRM implementation affecting multiple Snapdragon platforms. This allows...

May 7, 2021
CVE-2021-21784
7.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting an out-of-bounds write in Accusoft ImageGear's ...

Apr 13, 2021
CVE-2021-1479
7.8

CVE-2021-1479 allows unauthenticated remote attackers to execute arbitrary code on Cisco SD-WAN vManage software, or authenticated local attackers to ...

Apr 8, 2021
CVE-2021-1137
7.8

This vulnerability in Cisco SD-WAN vManage Software allows unauthenticated remote attackers to execute arbitrary code or authenticated local attackers...

Apr 8, 2021
CVE-2021-22709
7.8

This vulnerability in Schneider Electric's IGSC SCADA system allows attackers to execute arbitrary code or cause data loss by importing a malicious co...

Mar 11, 2021
CVE-2021-22711
7.8

This vulnerability in Schneider Electric's IGSC SCADA system allows attackers to execute arbitrary read or write operations by importing a malicious c...

Mar 11, 2021
CVE-2021-3410
7.8

This vulnerability is a buffer overflow in libcaca's caca_resize function that could allow local attackers to execute arbitrary code with the privileg...

Feb 23, 2021
CVE-2020-11180
7.8

CVE-2020-11180 is an out-of-bounds memory access vulnerability in Qualcomm Snapdragon chipsets' computer vision control due to improper command length...

Jan 21, 2021
CVE-2020-14360
7.8

This vulnerability in X.Org Server allows attackers to execute arbitrary code with elevated privileges by exploiting an out-of-bounds memory access in...

Jan 20, 2021
CVE-2021-1713
7.8

This vulnerability allows remote code execution when Microsoft Excel opens a specially crafted file. Attackers could exploit this to run arbitrary cod...

Jan 12, 2021
CVE-2020-13520
7.8

This vulnerability allows remote code execution through a memory corruption flaw in Pixar OpenUSD's file parsing. Attackers can craft malicious USD fi...

Dec 11, 2020
CVE-2020-7550
7.8

This vulnerability allows remote code execution when a malicious CGF file is imported into IGSS Definition software. Attackers can exploit a buffer ov...

Nov 19, 2020
CVE-2020-7554
7.8

This vulnerability allows remote code execution when a malicious CGF (Configuration Group File) is imported into IGSS Definition software. Attackers c...

Nov 19, 2020
CVE-2020-3603
7.8

This vulnerability allows remote code execution through malicious Webex recording files (ARF/WRF format). Attackers can exploit it by tricking users i...

Nov 6, 2020
CVE-2023-24585
7.7

An out-of-bounds write vulnerability in Weston Embedded uC-HTTP v3.01.01 allows remote attackers to cause memory corruption via specially crafted HTTP...

Nov 14, 2023
CVE-2021-34377
7.7

This vulnerability in NVIDIA's Trusty HDCP service TA allows attackers to bypass memory bounds checking, potentially leading to privilege escalation, ...

Jun 30, 2021
CVE-2025-43373
7.5

This CVE describes a memory corruption vulnerability in macOS kernel that could allow a malicious application to cause system crashes or corrupt kerne...

Nov 4, 2025
CVE-2025-60016
7.5

This vulnerability in F5 BIG-IP systems causes a denial of service when specific ECC Brainpool curves are configured in SSL profiles. Attackers can se...

Oct 15, 2025
CVE-2025-10225
7.5

A memory buffer vulnerability in AxxonSoft Axxon One's OpenSSL session module allows remote attackers to cause application crashes or unpredictable be...

Sep 10, 2025
CVE-2025-53713
7.5

A buffer overflow vulnerability in TP-Link TL-WR841N V11 routers allows remote attackers to crash the web service, causing denial-of-service. The vuln...

Jul 29, 2025
CVE-2025-53715
7.5

A buffer overflow vulnerability in TP-Link TL-WR841N V11 routers allows remote attackers to crash the web service, causing denial-of-service. The vuln...

Jul 29, 2025
CVE-2025-53711
7.5

A buffer overflow vulnerability in TP-Link TL-WR841N V11 routers allows remote attackers to crash the web service by sending specially crafted request...

Jul 29, 2025
CVE-2024-54551
7.5

This memory handling vulnerability in Apple's web content processing allows attackers to cause denial-of-service conditions. It affects users of Apple...

Mar 21, 2025
CVE-2024-52923
7.5

A boundary check vulnerability in Samsung's NRMM component for multiple Exynos processors allows denial of service attacks. Attackers can exploit this...

Mar 6, 2025
CVE-2024-31155
7.5

This UEFI firmware vulnerability in certain Intel processors allows privileged users to bypass buffer restrictions, potentially enabling local privile...

Feb 12, 2025
CVE-2023-49618
7.5

This vulnerability in Intel System Security Report and System Resources Defense firmware allows privileged users to bypass buffer restrictions, potent...

Feb 12, 2025
CVE-2025-0574
7.5

CVE-2025-0574 is a memory corruption vulnerability in Sante PACS Server's URL parsing that allows unauthenticated remote attackers to cause denial-of-...

Jan 30, 2025
CVE-2025-0568
7.5

This vulnerability allows remote attackers to cause denial-of-service on Sante PACS Server by sending specially crafted DCM files. Authentication is n...

Jan 30, 2025
CVE-2025-0569
7.5

This vulnerability allows remote attackers to cause denial-of-service on Sante PACS Server by sending specially crafted DCM files. The memory corrupti...

Jan 30, 2025
CVE-2024-11495
7.5

A buffer overflow vulnerability in OllyDbg 1.10 allows local attackers to execute arbitrary code by exploiting improper bounds checking. This affects ...

Nov 20, 2024
CVE-2024-11237
7.5

A critical stack-based buffer overflow vulnerability exists in the DHCP DISCOVER packet parser of TP-Link VN020 F3v(T) routers. Attackers can exploit ...

Nov 15, 2024
CVE-2024-27879
7.5

This CVE describes a memory corruption vulnerability in Apple iOS/iPadOS due to insufficient bounds checking. An attacker can cause unexpected app ter...

Sep 17, 2024
CVE-2024-36434
7.5

An SMM callout vulnerability in Supermicro X11DPH motherboards allows attackers with local access to execute arbitrary code in System Management Mode ...

Jul 15, 2024

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,195 CVEs classified as CWE-119, with 136 rated critical and 869 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free