CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,153
Total CVEs
119
Critical
845
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Linksys 22

All Buffer Overflow CVEs (1,153)

CVE-2025-5630
9.8

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web i...

Jun 5, 2025
CVE-2025-5624
9.8

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the QoS c...

Jun 5, 2025
CVE-2025-5622
9.8

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the wirel...

Jun 5, 2025
CVE-2025-5600
9.8

A critical stack-based buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by manipulating the...

Jun 4, 2025
CVE-2025-5408
9.8

A critical buffer overflow vulnerability in WAVLINK wireless routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 1, 2025
CVE-2025-35003
9.8

This CVE describes memory buffer and stack-based buffer overflow vulnerabilities in Apache NuttX RTOS's Bluetooth HCI and UART components. Attackers c...

May 26, 2025
CVE-2025-4638
9.8

A vulnerability in the zlib library's inftrees.c component, bundled within PointCloudLibrary (PCL), allows attackers to cause undefined behavior throu...

May 14, 2025
CVE-2025-2620
EPSS 35.6% 9.8

A critical stack-based buffer overflow vulnerability in D-Link DAP-1620's authentication handler allows remote attackers to execute arbitrary code or ...

Mar 22, 2025
CVE-2025-2618
9.8

A critical heap-based buffer overflow vulnerability in D-Link DAP-1620 access points allows remote attackers to execute arbitrary code or crash the de...

Mar 22, 2025
CVE-2025-1864
9.8

CVE-2025-1864 is a memory buffer overflow vulnerability in radare2, a reverse engineering framework. Attackers can exploit this to execute arbitrary c...

Mar 3, 2025
CVE-2024-9401
9.8

CVE-2024-9401 is a critical memory safety vulnerability in Mozilla Firefox and Thunderbird that could allow attackers to execute arbitrary code throug...

Oct 1, 2024
CVE-2024-20082
9.8

This critical vulnerability in MediaTek modem firmware allows remote attackers to execute arbitrary code without authentication or user interaction. I...

Aug 14, 2024
CVE-2024-22080
9.8

Unauthenticated attackers can exploit memory corruption during XML parsing in Elspec G5 digital fault recorders to execute arbitrary code or cause den...

Mar 20, 2024
CVE-2024-20011
9.8

This vulnerability in the ALAC (Apple Lossless Audio Codec) decoder allows remote attackers to execute arbitrary code without user interaction due to ...

Feb 5, 2024
CVE-2024-24561
9.8

This vulnerability in Vyper smart contract language allows attackers to bypass bounds checks for slice operations when non-literal arguments are used,...

Feb 1, 2024
CVE-2023-4494
9.8

A stack-based buffer overflow vulnerability in Easy Chat Server 3.1 allows remote attackers to execute arbitrary code by sending an excessively long u...

Oct 4, 2023
CVE-2023-4491
9.8

A buffer overflow vulnerability in Easy Address Book Web Server 1.6 allows remote attackers to execute arbitrary code by sending an overly long userna...

Oct 4, 2023
CVE-2023-44017
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10U routers by exploiting a stack overflow in the timeZone parameter. ...

Sep 27, 2023
CVE-2023-44019
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10U routers via a stack overflow in the GetParentControlInfo function....

Sep 27, 2023
CVE-2023-44021
9.8

This vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack overflow in the formSetClientState function. A...

Sep 27, 2023
CVE-2023-44023
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10U routers by exploiting a stack overflow in the WiFi configuration f...

Sep 27, 2023
CVE-2023-44013
9.8

This vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack overflow in the fromSetIpMacBind function. Att...

Sep 27, 2023
CVE-2023-44015
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10U routers by exploiting a stack overflow in the setSchedWifi functio...

Sep 27, 2023
CVE-2023-28581
9.8

This vulnerability allows memory corruption in WLAN firmware when parsing GTK keys in GTK KDE, potentially enabling remote code execution or denial of...

Sep 5, 2023
CVE-2022-46293
9.8

CVE-2022-46293 is a critical out-of-bounds write vulnerability in Open Babel's MOPAC file parser that allows arbitrary code execution when processing ...

Jul 21, 2023
CVE-2022-46295
9.8

CVE-2022-46295 is a critical out-of-bounds write vulnerability in Open Babel's Gaussian file format parser that allows arbitrary code execution when p...

Jul 21, 2023
CVE-2022-43467
9.8

This critical vulnerability in Open Babel allows arbitrary code execution through an out-of-bounds write when processing specially crafted PQS format ...

Jul 21, 2023
CVE-2022-46291
9.8

CVE-2022-46291 is a critical out-of-bounds write vulnerability in Open Babel's MSI file format parser that allows arbitrary code execution when proces...

Jul 21, 2023
CVE-2023-33975
9.8

CVE-2023-33975 is a critical memory corruption vulnerability in RIOT-OS's 6LoWPAN network stack that allows remote attackers to execute arbitrary code...

May 30, 2023
CVE-2021-46760
9.8

This vulnerability allows a malicious or compromised UApp or ABL to send malformed system calls to AMD bootloaders, potentially leading to out-of-boun...

May 9, 2023
CVE-2021-33797
9.8

This vulnerability is a buffer overflow in Artifex MuJS's floating-point parsing code that allows attackers to execute arbitrary code or crash applica...

Apr 17, 2023
CVE-2022-20238
9.8

This vulnerability in Android's kernel allows userspace applications to map kernel memory as writable through the 'remap_pfn_range' function. Attacker...

Jul 13, 2022
CVE-2021-46786
9.8

This vulnerability in Huawei audio modules allows attackers to trigger out-of-bounds memory access by passing malicious parameters. It affects Huawei ...

May 13, 2022
CVE-2021-44496
9.8

This vulnerability in FIS GT.M (and related YottaDB) allows attackers to execute arbitrary code by exploiting a buffer overflow in memcpy. Attackers c...

Apr 15, 2022
CVE-2021-22432
9.8

This vulnerability in Huawei smartphones allows attackers to bypass permission isolation mechanisms, potentially leading to out-of-bounds memory acces...

Feb 25, 2022
CVE-2021-22434
9.8

CVE-2021-22434 is a critical memory address out-of-bounds vulnerability affecting certain Huawei smartphones running HarmonyOS. Successful exploitatio...

Feb 25, 2022
CVE-2021-22426
9.8

CVE-2021-22426 is a critical memory corruption vulnerability in Huawei smartphones that allows attackers to execute arbitrary code by exploiting out-o...

Feb 25, 2022
CVE-2021-20325
9.8

CVE-2021-20325 is a Red Hat-specific security regression where fixes for CVE-2021-40438 and CVE-2021-26691 were missing in httpd packages shipped with...

Feb 18, 2022
CVE-2021-3657
9.8

This vulnerability in mbsync allows remote attackers to execute arbitrary code by exploiting buffer overflows when processing extremely large IMAP lit...

Feb 18, 2022
CVE-2021-31617
9.8

This vulnerability in Stormshield Network Security (SNS) ASQ allows remote attackers to execute arbitrary code due to improper memory management. It a...

Jan 31, 2022
CVE-2021-45709
9.8

CVE-2021-45709 is a memory safety vulnerability in the crypto2 Rust crate that allows unaligned memory reads during Chacha20 encryption/decryption ope...

Dec 27, 2021
CVE-2021-44538
9.8

A buffer overflow vulnerability in Matrix libolm's olm_session_describe function allows remote attackers to execute arbitrary code or cause denial of ...

Dec 14, 2021
CVE-2021-37002
9.8

This is a critical memory corruption vulnerability in Huawei smartphones that allows attackers to execute arbitrary code by exploiting out-of-bounds m...

Oct 28, 2021
CVE-2021-1770
9.8

CVE-2021-1770 is a critical buffer overflow vulnerability in Apple operating systems that could allow attackers to execute arbitrary code on affected ...

Sep 8, 2021
CVE-2021-32992
9.8

This is a critical buffer overflow vulnerability in FATEK Automation WinProladder software that allows remote attackers to execute arbitrary code on a...

Jun 29, 2021
CVE-2020-15782
9.8

This vulnerability allows remote unauthenticated attackers to bypass memory protection on Siemens industrial control systems. By sending specially cra...

May 28, 2021
CVE-2021-20204
9.8

CVE-2021-20204 is a critical heap memory corruption vulnerability (use-after-free) in libgetdata v0.10.0 that allows attackers to execute arbitrary co...

May 6, 2021
CVE-2021-1459
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code as root on affected Cisco Small Business routers via cra...

Apr 8, 2021
CVE-2021-30454
9.8

This vulnerability in the outer_cgi Rust crate allows attackers to read uninitialized memory from a server's process, potentially exposing sensitive d...

Apr 7, 2021
CVE-2021-22714
9.8

This vulnerability is a memory buffer overflow in Schneider Electric PowerLogic meters that could allow attackers to cause denial of service (reboots)...

Mar 11, 2021

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,153 CVEs classified as CWE-119, with 119 rated critical and 845 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free