CWE-119: Buffer Overflow
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Yearly Trend
Top Affected Vendors
All Buffer Overflow CVEs (1,224)
This vulnerability in NVIDIA Jetson Linux Driver Package allows local attackers with elevated privileges to exploit a memory buffer overflow in the Cb...
Apr 27, 2022A remote stack-based buffer overflow vulnerability in Wavlink WL-NU516U1 router's login.cgi component allows attackers to execute arbitrary code by ma...
Mar 6, 2026A buffer overflow vulnerability in the UTT HiPER 810G router's administrative interface allows remote attackers to execute arbitrary code by manipulat...
Feb 23, 2026This CVE describes a remote buffer overflow vulnerability in UTT HiPER 810G routers. Attackers can exploit the strcpy function in the ConfigExceptMSN ...
Feb 22, 2026A remote stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1 routers through firmware version 130/260. Attackers can exploit this b...
Feb 16, 2026A stack-based buffer overflow vulnerability exists in Tenda AC9 routers running firmware version 15.03.06.42_multi. Remote attackers can exploit this ...
Feb 8, 2026This CVE describes a stack-based buffer overflow vulnerability in Tenda AC9 routers' formGetRebootTimer function. Attackers can exploit this remotely ...
Feb 8, 2026A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...
Dec 29, 2025This vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the HTTP request hand...
Dec 29, 2025A stack-based buffer overflow vulnerability in Tenda WH450 router firmware version 1.0.0.18 allows remote attackers to execute arbitrary code by manip...
Dec 29, 2025A stack-based buffer overflow vulnerability in Tenda WH450 router firmware version 1.0.0.18 allows remote attackers to execute arbitrary code by sendi...
Dec 29, 2025This vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the SafeEmailFilter f...
Dec 29, 2025A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parame...
Dec 29, 2025A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parame...
Dec 29, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers via a stack-based buffer overflow in the PPTPServer compon...
Dec 28, 2025A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'delno' param...
Dec 28, 2025A buffer overflow vulnerability in UGREEN DH2100+ NAS devices allows remote attackers to execute arbitrary code by manipulating the 'path' parameter i...
Dec 7, 2025A buffer restriction vulnerability in Intel Xeon Processor firmware with SGX enabled allows privileged users to potentially escalate privileges via lo...
Aug 12, 2025A critical stack-based buffer overflow vulnerability in D-Link DI-8100 routers allows remote attackers to execute arbitrary code by manipulating param...
May 18, 2025CVE-2024-42442 is a memory buffer vulnerability in AMI APTIOV BIOS that allows network-based attackers to execute arbitrary code outside System Manage...
Nov 12, 2024This CVE describes a memory overflow vulnerability in certain Huawei smart speakers. Successful exploitation could cause certain functions to fail, po...
May 28, 2024This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on Cisco ASA and FTD devices by exploiting ins...
Sep 23, 2020This is a memory corruption vulnerability in Apple operating systems that could allow an attacker to cause system crashes or corrupt kernel memory. It...
May 12, 2025CVE-2024-33258 is a memory corruption vulnerability in JerryScript's JavaScript engine that allows attackers to cause segmentation faults via speciall...
Apr 26, 2024This vulnerability allows a malicious app to corrupt coprocessor memory on Apple devices, potentially leading to arbitrary code execution or system in...
Apr 24, 2024A buffer overflow vulnerability in Delta Electronics DOPSoft version 2 allows remote code execution when parsing malicious DPS files. Attackers can ex...
Jan 18, 2024This macOS kernel vulnerability allows malicious applications to bypass memory bounds checks, potentially causing system crashes or writing to kernel ...
Jan 10, 2024This vulnerability in OpenSC allows attackers to trigger a heap-based buffer out-of-bounds read by sending a specially crafted smart card package with...
Jun 1, 2023This vulnerability affects Siemens Capital Embedded AR Classic products where the DHCP client fails to validate vendor option lengths in DHCP ACK mess...
Nov 9, 2021CVE-2021-3561 is an out-of-bounds memory access vulnerability in fig2dev's read_objects() function that allows attackers to crash the application or p...
May 26, 2021CVE-2023-36747 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser. Attackers can exploit this by tricking users into opening m...
Jan 8, 2024Snappier 1.1.0 contains a buffer overrun vulnerability due to byte references briefly pointing outside valid buffer areas during garbage collection co...
Mar 27, 2023A race condition vulnerability in Xen's event channel reset mechanism allows x86 PV guests to potentially escalate privileges to host level, cause hos...
Sep 23, 2020This vulnerability allows an attacker to cause memory corruption by providing a crafted argument to a system call. This affects systems running vulner...
Sep 18, 2025A memory corruption vulnerability in the Linux kernel's HID subsystem allows local attackers to crash the system or potentially escalate privileges by...
Mar 27, 2023This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It af...
Feb 11, 2026This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It af...
Feb 11, 2026An attacker on the same network can crash the UniFi Protect Application by sending specially crafted discovery protocol packets. This affects all UniF...
Jan 5, 2026YAML::Syck versions before 1.36 for Perl have a missing null-terminator vulnerability in token.c that causes out-of-bounds reads when processing compl...
Oct 16, 2025A memory handling vulnerability in Apple WebKit (CWE-119) allows malicious web content to cause Safari to crash unexpectedly. This affects users of Sa...
Jul 30, 2025This CVE describes a memory handling vulnerability in Apple's Safari browser and related WebKit components across multiple Apple operating systems. Pr...
Jul 30, 2025This memory handling vulnerability in Apple's AirPlay and CarPlay SDKs allows attackers on the same local network to cause application crashes through...
Apr 30, 2025CVE-2025-29492 is a memory corruption vulnerability in libming v0.4.8 that causes a segmentation fault in the decompileSETVARIABLE function. This vuln...
Mar 27, 2025CVE-2025-29494 is a memory corruption vulnerability in libming v0.4.8's decompileGETMEMBER function that causes a segmentation fault when processing m...
Mar 27, 2025CVE-2025-29485 is a memory corruption vulnerability in libming v0.4.8 that causes a segmentation fault when processing specially crafted SWF files. At...
Mar 27, 2025A critical buffer overflow vulnerability in Tenda TX3 routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...
Mar 4, 2025A critical buffer overflow vulnerability in Tenda TX3 routers allows remote attackers to execute arbitrary code by manipulating the schedStartTime/sch...
Mar 4, 2025This vulnerability allows authenticated remote attackers to cause denial-of-service conditions on Sante PACS Server installations by sending specially...
Jan 30, 2025A critical stack-based buffer overflow vulnerability in Tenda A18 routers allows remote attackers to execute arbitrary code by sending specially craft...
Jan 30, 2025This CVE describes a buffer overflow vulnerability in Schneider Electric devices that allows unauthorized attackers to send malicious Modbus write pac...
Jan 17, 2025About Buffer Overflow (CWE-119)
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Our database tracks 1,224 CVEs classified as CWE-119, with 144 rated critical and 889 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-119 on MITRE CWE →
Monitor Buffer Overflow Vulnerabilities
Get alerted when new Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free