CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,198
Total CVEs
138
Critical
870
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
170
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Fedoraproject 24
10 Mozilla 24

All Buffer Overflow CVEs (1,198)

CVE-2024-11237
7.5

A critical stack-based buffer overflow vulnerability exists in the DHCP DISCOVER packet parser of TP-Link VN020 F3v(T) routers. Attackers can exploit ...

Nov 15, 2024
CVE-2024-27879
7.5

This CVE describes a memory corruption vulnerability in Apple iOS/iPadOS due to insufficient bounds checking. An attacker can cause unexpected app ter...

Sep 17, 2024
CVE-2024-36434
7.5

An SMM callout vulnerability in Supermicro X11DPH motherboards allows attackers with local access to execute arbitrary code in System Management Mode ...

Jul 15, 2024
CVE-2024-20076
7.5

This vulnerability in MediaTek modems allows remote attackers to cause a system crash through incorrect error handling, leading to denial of service w...

Jul 1, 2024
CVE-2024-23980
7.5

This vulnerability in the PlatformPfrDxe driver of UEFI firmware for certain Intel Server D50FCP Family products allows a privileged user to escalate ...

May 16, 2024
CVE-2024-30253
7.5

A memory exhaustion vulnerability in @solana/web3.js allows attackers to crash applications by providing malicious inputs. This affects any server, cl...

Apr 17, 2024
CVE-2024-30398
7.5

An unauthenticated network attacker can cause a denial of service on Juniper SRX4600 devices by sending specific high-volume traffic that triggers a m...

Apr 12, 2024
CVE-2024-22041
7.5

A memory buffer handling vulnerability in the network communication library of Siemens Cerberus and related fire safety systems allows unauthenticated...

Mar 12, 2024
CVE-2023-32331
7.5

CVE-2023-32331 is a buffer overflow vulnerability in IBM Connect:Express for UNIX 1.5.0 that allows remote attackers to cause denial of service throug...

Mar 4, 2024
CVE-2024-24476
7.5

This CVE describes a disputed buffer overflow vulnerability in Wireshark's address resolution and manufacturer lookup components that could allow remo...

Feb 21, 2024
CVE-2023-43817
7.5

A buffer overflow vulnerability in Delta Electronics DOPSoft version 2 allows remote code execution when parsing malicious DPS files. Attackers can ex...

Jan 18, 2024
CVE-2023-39616
7.5

CVE-2023-39616 is a memory corruption vulnerability in AOMedia's AV1 video codec library (libaom) versions 3.0.0 through 3.5.0. An invalid read memory...

Aug 29, 2023
CVE-2023-3261
7.5

A buffer overflow vulnerability in Dataprobe iBoot PDU firmware allows attackers to cause denial of service or disrupt login functionality via the web...

Aug 14, 2023
CVE-2023-3138
7.5

A memory corruption vulnerability in libX11 allows malicious X servers or man-in-the-middle proxies to crash X11 client applications. The flaw occurs ...

Jun 28, 2023
CVE-2023-24817
7.5

CVE-2023-24817 is an integer underflow vulnerability in RIOT-OS's 6LoWPAN network stack that allows attackers to send crafted frames causing out-of-bo...

May 30, 2023
CVE-2023-0202
7.5

This vulnerability in NVIDIA DGX A100 SBIOS allows attackers to modify arbitrary memory in SMRAM (System Management RAM) by exploiting SMM (System Man...

Apr 22, 2023
CVE-2023-0206
7.5

This vulnerability in NVIDIA DGX A100 SBIOS allows attackers to modify SMRAM memory through the NVME SMM API. Successful exploitation could lead to de...

Apr 22, 2023
CVE-2022-34423
7.5

This vulnerability allows a local malicious user with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and ...

Mar 16, 2023
CVE-2022-34421
7.5

This vulnerability allows a local malicious user with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and ...

Mar 16, 2023
CVE-2022-34409
7.5

This vulnerability allows a local attacker with high privileges to exploit improper buffer verification in Dell PowerEdge and Precision BIOS System Ma...

Mar 16, 2023
CVE-2022-34411
7.5

This vulnerability allows a local attacker with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and Precis...

Mar 16, 2023
CVE-2022-34413
7.5

This vulnerability allows a local malicious user with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and ...

Mar 16, 2023
CVE-2022-34415
7.5

This vulnerability allows a local attacker with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and Precis...

Mar 16, 2023
CVE-2022-34417
7.5

This vulnerability allows a local attacker with high privileges to exploit improper buffer verification in Dell PowerEdge and Precision BIOS System Ma...

Mar 16, 2023
CVE-2022-34419
7.5

This vulnerability allows a local malicious user with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and ...

Mar 16, 2023
CVE-2022-34407
7.5

This vulnerability allows a local malicious user with high privileges to exploit improper SMM communication buffer verification in Dell PowerEdge and ...

Mar 16, 2023
CVE-2022-35911
7.5

CVE-2022-35911 is a buffer overflow vulnerability in Patlite NH-FB series devices that allows remote attackers to cause denial of service by sending r...

Jul 27, 2022
CVE-2022-30937
7.5

A memory corruption vulnerability in Siemens EN100 Ethernet modules allows attackers to cause denial of service by sending specially crafted HTTP pack...

Jun 14, 2022
CVE-2021-40400
7.5

An out-of-bounds read vulnerability in Gerbv's RS-274X aperture macro outline primitive allows attackers to read memory beyond allocated buffers via s...

Apr 14, 2022
CVE-2021-40368
7.5

This vulnerability affects multiple Siemens SIMATIC S7-400 and S7-410 industrial controllers. An attacker can send specially crafted packets to TCP po...

Apr 12, 2022
CVE-2021-36343
7.5

Dell BIOS contains an improper input validation vulnerability that allows a local authenticated malicious user to exploit System Management Interrupt ...

Jan 24, 2022
CVE-2021-46020
7.5

This vulnerability involves an untrusted pointer dereference in mruby's virtual machine execution function, which can cause a segmentation fault and c...

Jan 14, 2022
CVE-2021-41771
7.5

This vulnerability in Go's debug/macho package allows attackers to read memory beyond allocated buffer boundaries when parsing Mach-O files. It affect...

Nov 8, 2021
CVE-2021-41121
7.5

CVE-2021-41121 is a memory corruption vulnerability in Vyper smart contract language that occurs when performing function calls inside literal structs...

Oct 6, 2021
CVE-2021-33737
7.5

A denial-of-service vulnerability in Siemens SIMATIC CP industrial communication modules allows remote attackers to crash affected devices by sending ...

Sep 14, 2021
CVE-2021-38201
7.5

This vulnerability in the Linux kernel's NFS client implementation allows remote attackers to cause a denial of service through slab-out-of-bounds mem...

Aug 8, 2021
CVE-2021-27477
7.5

This vulnerability in JTEKT Corporation TOYOPUC PLCs allows an attacker to cause a denial of service by sending specially crafted invalid frames to th...

Jul 1, 2021
CVE-2021-1510
7.5

This vulnerability in Cisco SD-WAN vEdge Software allows attackers to execute arbitrary code as root or cause denial of service through buffer overflo...

May 6, 2021
CVE-2015-20001
7.5

This vulnerability in Rust's standard library before version 1.2.0 allows memory safety violations when BinaryHeap operations panic. It affects any Ru...

Apr 11, 2021
CVE-2021-28877
7.5

This vulnerability in Rust's standard library before version 1.51.0 allows memory safety violations when using nested Zip iterators. The bug causes th...

Apr 11, 2021
CVE-2021-22713
7.5

This vulnerability is a memory buffer overflow in Schneider Electric PowerLogic ION series power meters that could allow an attacker to cause denial o...

Mar 11, 2021
CVE-2021-20276
7.5

This vulnerability in Privoxy allows an attacker to cause denial of service by passing invalid patterns to the pcre_compile() function, leading to inv...

Mar 9, 2021
CVE-2025-48429
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's RLECodec::DecodeByStreams function allows attackers to leak heap memory data by providing a s...

Dec 16, 2025
CVE-2025-52582
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's Overlay::GrabOverlayFromPixelData function allows attackers to leak sensitive information by ...

Dec 16, 2025
CVE-2025-53618
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

Dec 16, 2025
CVE-2025-53619
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

Dec 16, 2025
CVE-2025-36156
7.4

A local attacker with access to specific files (CECSUB or CECRM) on IBM InfoSphere Data Replication VSAM for z/OS can exploit a stack-based buffer ove...

Oct 7, 2025
CVE-2025-30437
7.4

This vulnerability in macOS allows malicious applications to corrupt coprocessor memory due to insufficient bounds checking. It affects macOS systems ...

Mar 31, 2025
CVE-2021-25217
7.4

A memory corruption vulnerability in ISC DHCP allows attackers to cause denial of service by crashing dhclient or dhcpd processes when they parse mali...

May 26, 2021
CVE-2021-1308
7.4

This vulnerability allows an unauthenticated attacker on the same network segment to execute arbitrary code, leak memory, or cause denial of service o...

Apr 8, 2021

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,198 CVEs classified as CWE-119, with 138 rated critical and 870 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free