CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,220
Total CVEs
143
Critical
886
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
177
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 25
9 Freefloat 25
10 Mozilla 24

All Buffer Overflow CVEs (1,220)

CVE-2025-5049
7.3

CVE-2025-5049 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's APPEND command handler that allows remote attackers to execute...

May 21, 2025
CVE-2025-4871
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

May 18, 2025
CVE-2025-4847
7.3

A critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's MLS command handler allows remote attackers to execute arbitrary code or crash ...

May 18, 2025
CVE-2025-4845
7.3

A critical buffer overflow vulnerability exists in FreeFloat FTP Server 1.0's TRACE command handler, allowing remote attackers to execute arbitrary co...

May 18, 2025
CVE-2025-4792
7.3

CVE-2025-4792 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's MDELETE command handler that allows remote attackers to execut...

May 16, 2025
CVE-2025-4788
7.3

CVE-2025-4788 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's DELETE command handler that allows remote attackers to execute...

May 16, 2025
CVE-2025-4790
7.3

CVE-2025-4790 is a critical buffer overflow vulnerability in FreeFloat FTP Server 1.0's GLOB command handler that allows remote attackers to execute a...

May 16, 2025
CVE-2024-36292
7.3

An improper buffer restriction vulnerability in Intel Data Center GPU Flex Series drivers for Windows allows authenticated local users to cause denial...

May 13, 2025
CVE-2025-4288
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code via the RNFR command handler. Thi...

May 5, 2025
CVE-2025-4255
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service via the RMD ...

May 5, 2025
CVE-2025-4253
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server 2.0.7's HASH command handler, allowing remote attackers to execute arbitrary code ...

May 4, 2025
CVE-2025-4251
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

May 4, 2025
CVE-2025-4240
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server 2.0.7's LCD Command Handler component, allowing remote attackers to execute arbitr...

May 3, 2025
CVE-2025-4238
7.3

CVE-2025-4238 is a critical buffer overflow vulnerability in PCMan FTP Server 2.0.7's MGET command handler that allows remote attackers to execute arb...

May 3, 2025
CVE-2025-4236
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server 2.0.7's MDIR command handler, allowing remote attackers to execute arbitrary code ...

May 3, 2025
CVE-2025-4162
7.3

A critical buffer overflow vulnerability in PCMan FTP Server's ASCII command handler allows remote attackers to execute arbitrary code or crash the se...

May 1, 2025
CVE-2025-4160
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server's LS command handler, allowing remote attackers to execute arbitrary code or crash...

May 1, 2025
CVE-2025-4158
7.3

A critical buffer overflow vulnerability in PCMan FTP Server's PROMPT command handler allows remote attackers to execute arbitrary code or crash the s...

May 1, 2025
CVE-2025-4079
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server's RENAME command handler, allowing remote attackers to execute arbitrary code or c...

Apr 29, 2025
CVE-2025-3845
7.3

A critical buffer overflow vulnerability in markparticle WebServer up to version 1.0 allows remote attackers to execute arbitrary code or cause denial...

Apr 21, 2025
CVE-2025-3762
7.3

CVE-2025-3762 is a critical buffer overflow vulnerability in PCMan FTP Server 2.0.7's MPUT command handler that allows remote attackers to execute arb...

Apr 17, 2025
CVE-2025-3727
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Apr 16, 2025
CVE-2025-3725
7.3

A critical buffer overflow vulnerability exists in PCMan FTP Server 2.0.7's MIC command handler, allowing remote attackers to execute arbitrary code o...

Apr 16, 2025
CVE-2025-3723
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by exploitin...

Apr 16, 2025
CVE-2025-3683
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code by sending specially crafted SIZE...

Apr 16, 2025
CVE-2025-3679
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Apr 16, 2025
CVE-2025-3681
7.3

CVE-2025-3681 is a critical buffer overflow vulnerability in PCMan FTP Server 2.0.7's MODE command handler that allows remote attackers to execute arb...

Apr 16, 2025
CVE-2025-3678
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code by sending specially crafted HELP...

Apr 16, 2025
CVE-2025-3379
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Apr 7, 2025
CVE-2025-3377
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Apr 7, 2025
CVE-2025-3375
7.3

CVE-2025-3375 is a critical buffer overflow vulnerability in PCMan FTP Server 2.0.7's CDUP command handler that allows remote attackers to execute arb...

Apr 7, 2025
CVE-2025-3373
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code or crash the service by sending s...

Apr 7, 2025
CVE-2025-3372
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code by sending specially crafted MKDI...

Apr 7, 2025
CVE-2025-3349
7.3

A critical buffer overflow vulnerability in PCMan FTP Server 2.0.7 allows remote attackers to execute arbitrary code by sending a specially crafted SY...

Apr 7, 2025
CVE-2025-3266
7.3

A critical stack-based buffer overflow vulnerability exists in qinguoyi TinyWebServer versions up to 1.0, specifically in the /http/http_conn.cpp file...

Apr 4, 2025
CVE-2024-12988
7.3

A critical buffer overflow vulnerability in Netgear R6900P and R7000P routers allows remote attackers to execute arbitrary code by sending specially c...

Dec 27, 2024
CVE-2023-6361
7.3

This CVE describes a buffer overflow vulnerability in Winhex that allows attackers to execute arbitrary code by providing a specially crafted long fil...

Oct 7, 2024
CVE-2024-9403
7.3

CVE-2024-9403 is a memory safety vulnerability in Firefox and Thunderbird that could allow memory corruption. With sufficient effort, attackers could ...

Oct 1, 2024
CVE-2024-0338
7.3

A buffer overflow vulnerability in XAMPP versions 8.2.4 and earlier allows attackers to execute arbitrary code by exploiting a Structured Exception Ha...

Feb 2, 2024
CVE-2024-1112
7.3

A heap-based buffer overflow vulnerability in Resource Hacker version 3.6.0.92 allows attackers to execute arbitrary code by providing a specially cra...

Jan 31, 2024
CVE-2024-0429
7.3

A buffer overflow vulnerability in Hex Workshop 6.7 allows attackers to trigger a denial of service by manipulating command line arguments to corrupt ...

Jan 11, 2024
CVE-2022-37331
7.3

An out-of-bounds write vulnerability in Open Babel's Gaussian format orientation functionality allows arbitrary code execution when processing malicio...

Jul 21, 2023
CVE-2014-125024
7.3

This critical vulnerability in FFmpeg 2.0 allows remote attackers to execute arbitrary code or cause denial of service through memory corruption in th...

Jun 19, 2022
CVE-2014-125020
7.3

This critical vulnerability in FFmpeg 2.0 allows remote attackers to trigger memory corruption via the decode_update_thread_context function, potentia...

Jun 19, 2022
CVE-2014-125017
7.3

This critical vulnerability in FFmpeg 2.0 allows remote attackers to cause memory corruption through the rpza_decode_stream function, potentially lead...

Jun 18, 2022
CVE-2014-125015
7.3

This critical vulnerability in FFmpeg 2.0 allows remote attackers to trigger memory corruption through the read_var_block_data function. Attackers can...

Jun 18, 2022
CVE-2022-28194
7.3

This vulnerability in NVIDIA Jetson Linux Driver Package allows local attackers with elevated privileges to exploit a memory buffer overflow in the Cb...

Apr 27, 2022
CVE-2026-3613
7.2

A remote stack-based buffer overflow vulnerability in Wavlink WL-NU516U1 router's login.cgi component allows attackers to execute arbitrary code by ma...

Mar 6, 2026
CVE-2026-2980
7.2

A buffer overflow vulnerability in the UTT HiPER 810G router's administrative interface allows remote attackers to execute arbitrary code by manipulat...

Feb 23, 2026
CVE-2026-2935
7.2

This CVE describes a remote buffer overflow vulnerability in UTT HiPER 810G routers. Attackers can exploit the strcpy function in the ConfigExceptMSN ...

Feb 22, 2026

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,220 CVEs classified as CWE-119, with 143 rated critical and 886 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free