CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,217
Total CVEs
142
Critical
884
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
175
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 25
9 Freefloat 25
10 Mozilla 24

All Buffer Overflow CVEs (1,217)

CVE-2021-38201
7.5

This vulnerability in the Linux kernel's NFS client implementation allows remote attackers to cause a denial of service through slab-out-of-bounds mem...

Aug 8, 2021
CVE-2021-27477
7.5

This vulnerability in JTEKT Corporation TOYOPUC PLCs allows an attacker to cause a denial of service by sending specially crafted invalid frames to th...

Jul 1, 2021
CVE-2021-1510
7.5

This vulnerability in Cisco SD-WAN vEdge Software allows attackers to execute arbitrary code as root or cause denial of service through buffer overflo...

May 6, 2021
CVE-2015-20001
7.5

This vulnerability in Rust's standard library before version 1.2.0 allows memory safety violations when BinaryHeap operations panic. It affects any Ru...

Apr 11, 2021
CVE-2021-28877
7.5

This vulnerability in Rust's standard library before version 1.51.0 allows memory safety violations when using nested Zip iterators. The bug causes th...

Apr 11, 2021
CVE-2021-22713
7.5

This vulnerability is a memory buffer overflow in Schneider Electric PowerLogic ION series power meters that could allow an attacker to cause denial o...

Mar 11, 2021
CVE-2021-20276
7.5

This vulnerability in Privoxy allows an attacker to cause denial of service by passing invalid patterns to the pcre_compile() function, leading to inv...

Mar 9, 2021
CVE-2020-1671
7.5

A vulnerability in Juniper Networks Junos OS DHCPv6 implementation allows remote attackers to crash the JDHCPD process by sending malformed DHCPv6 pac...

Oct 16, 2020
CVE-2025-48429
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's RLECodec::DecodeByStreams function allows attackers to leak heap memory data by providing a s...

Dec 16, 2025
CVE-2025-52582
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's Overlay::GrabOverlayFromPixelData function allows attackers to leak sensitive information by ...

Dec 16, 2025
CVE-2025-53618
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

Dec 16, 2025
CVE-2025-53619
7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

Dec 16, 2025
CVE-2025-36156
7.4

A local attacker with access to specific files (CECSUB or CECRM) on IBM InfoSphere Data Replication VSAM for z/OS can exploit a stack-based buffer ove...

Oct 7, 2025
CVE-2025-30437
7.4

This vulnerability in macOS allows malicious applications to corrupt coprocessor memory due to insufficient bounds checking. It affects macOS systems ...

Mar 31, 2025
CVE-2021-25217
7.4

A memory corruption vulnerability in ISC DHCP allows attackers to cause denial of service by crashing dhclient or dhcpd processes when they parse mali...

May 26, 2021
CVE-2021-1308
7.4

This vulnerability allows an unauthenticated attacker on the same network segment to execute arbitrary code, leak memory, or cause denial of service o...

Apr 8, 2021
CVE-2021-0217
7.4

This vulnerability allows adjacent attackers to send specially crafted DHCP packets to Juniper EX/QFX Series switches running vulnerable Junos OS vers...

Jan 15, 2021
CVE-2025-61144
7.3

A stack overflow vulnerability in libtiff's readSeparateStripsIntoBuffer function allows attackers to execute arbitrary code or cause denial of servic...

Feb 23, 2026
CVE-2026-2940
7.3

This CVE describes a remote out-of-bounds write vulnerability in Zaher1307's tiny_web_server that could allow attackers to execute arbitrary code or c...

Feb 22, 2026
CVE-2025-15555
7.3

A stack-based buffer overflow vulnerability in Open5GS allows remote attackers to execute arbitrary code or cause denial of service by manipulating th...

Feb 4, 2026
CVE-2026-0821
7.3

A heap-based buffer overflow vulnerability in quickjs-ng's js_typed_array_constructor function allows remote attackers to execute arbitrary code or ca...

Jan 10, 2026
CVE-2025-15247
7.3

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a heap-based buffer overflow in the snap7-rs libra...

Dec 30, 2025
CVE-2025-15008
7.3

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Dec 22, 2025
CVE-2025-14673
7.3

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a heap-based buffer overflow in the snap7-rs libra...

Dec 14, 2025
CVE-2025-14672
7.3

A heap-based buffer overflow vulnerability exists in the snap7-rs library's TSnap7MicroClient::opWriteArea function. This allows remote attackers to e...

Dec 14, 2025
CVE-2025-5667
7.3

CVE-2025-5667 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's REIN command handler that allows remote attackers to execute a...

Jun 5, 2025
CVE-2025-5665
7.3

CVE-2025-5665 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's XCWD command handler that allows remote attackers to execute a...

Jun 5, 2025
CVE-2025-5637
7.3

CVE-2025-5637 is a critical buffer overflow vulnerability in PCMan FTP Server 2.0.7's SYSTEM command handler that allows remote attackers to execute a...

Jun 5, 2025
CVE-2025-5634
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Jun 5, 2025
CVE-2025-5595
7.3

CVE-2025-5595 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's PROGRESS command handler that allows remote attackers to execu...

Jun 4, 2025
CVE-2025-5593
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's HOST command handler allows remote attackers to execute arbitrary code or crash...

Jun 4, 2025
CVE-2025-5592
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's PASSIVE command handler allows remote attackers to execute arbitrary code or cr...

Jun 4, 2025
CVE-2025-5551
7.3

CVE-2025-5551 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's SYSTEM command handler that allows remote attackers to execute...

Jun 4, 2025
CVE-2025-5549
7.3

CVE-2025-5549 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's PASV command handler that allows remote attackers to execute a...

Jun 4, 2025
CVE-2025-5547
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's CDUP command handler allows remote attackers to execute arbitrary code or crash...

Jun 4, 2025
CVE-2025-5357
7.3

CVE-2025-5357 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's PWD command handler that allows remote attackers to execute ar...

May 30, 2025
CVE-2025-5356
7.3

A critical buffer overflow vulnerability exists in FreeFloat FTP Server 1.0's BYE command handler, allowing remote attackers to execute arbitrary code...

May 30, 2025
CVE-2025-5331
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

May 29, 2025
CVE-2025-5295
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0.0 allows remote attackers to execute arbitrary code via the PORT command handler....

May 28, 2025
CVE-2025-5221
7.3

CVE-2025-5221 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0.0's QUOTE command handler that allows remote attackers to execut...

May 27, 2025
CVE-2025-5220
7.3

CVE-2025-5220 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0.0's GET command handler that allows remote attackers to execute ...

May 27, 2025
CVE-2025-5217
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0.0 allows remote attackers to execute arbitrary code or crash the service by sendi...

May 27, 2025
CVE-2025-5219
7.3

A critical buffer overflow vulnerability exists in FreeFloat FTP Server 1.0.0's ASCII Command Handler component. This allows remote attackers to execu...

May 27, 2025
CVE-2025-5076
7.3

CVE-2025-5076 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's SEND command handler that allows remote attackers to execute a...

May 22, 2025
CVE-2025-5075
7.3

CVE-2025-5075 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's DEBUG command handler that allows remote attackers to execute ...

May 22, 2025
CVE-2025-5073
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0 allows remote attackers to execute arbitrary code or crash the service by sending...

May 22, 2025
CVE-2025-5052
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's LS command handler allows remote attackers to execute arbitrary code or crash t...

May 21, 2025
CVE-2025-5049
7.3

CVE-2025-5049 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's APPEND command handler that allows remote attackers to execute...

May 21, 2025
CVE-2025-4871
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

May 18, 2025
CVE-2025-4847
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's MLS command handler allows remote attackers to execute arbitrary code or crash ...

May 18, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,217 CVEs classified as CWE-119, with 142 rated critical and 884 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free