CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,224
Total CVEs
144
Critical
889
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
179
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 26
9 Freefloat 25
10 Mozilla 24

All Buffer Overflow CVEs (1,224)

CVE-2022-28194
7.3

This vulnerability in NVIDIA Jetson Linux Driver Package allows local attackers with elevated privileges to exploit a memory buffer overflow in the Cb...

Apr 27, 2022
CVE-2026-3613
7.2

A remote stack-based buffer overflow vulnerability in Wavlink WL-NU516U1 router's login.cgi component allows attackers to execute arbitrary code by ma...

Mar 6, 2026
CVE-2026-2980
7.2

A buffer overflow vulnerability in the UTT HiPER 810G router's administrative interface allows remote attackers to execute arbitrary code by manipulat...

Feb 23, 2026
CVE-2026-2935
7.2

This CVE describes a remote buffer overflow vulnerability in UTT HiPER 810G routers. Attackers can exploit the strcpy function in the ConfigExceptMSN ...

Feb 22, 2026
CVE-2026-2566
7.2

A remote stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1 routers through firmware version 130/260. Attackers can exploit this b...

Feb 16, 2026
CVE-2026-2191
7.2

A stack-based buffer overflow vulnerability exists in Tenda AC9 routers running firmware version 15.03.06.42_multi. Remote attackers can exploit this ...

Feb 8, 2026
CVE-2026-2192
7.2

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC9 routers' formGetRebootTimer function. Attackers can exploit this remotely ...

Feb 8, 2026
CVE-2025-15180
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Dec 29, 2025
CVE-2025-15178
7.2

This vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the HTTP request hand...

Dec 29, 2025
CVE-2025-15179
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 router firmware version 1.0.0.18 allows remote attackers to execute arbitrary code by manip...

Dec 29, 2025
CVE-2025-15177
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 router firmware version 1.0.0.18 allows remote attackers to execute arbitrary code by sendi...

Dec 29, 2025
CVE-2025-15163
7.2

This vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the SafeEmailFilter f...

Dec 29, 2025
CVE-2025-15164
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parame...

Dec 29, 2025
CVE-2025-15162
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parame...

Dec 29, 2025
CVE-2025-15160
7.2

This vulnerability allows remote attackers to execute arbitrary code on Tenda WH450 routers via a stack-based buffer overflow in the PPTPServer compon...

Dec 28, 2025
CVE-2025-15161
7.2

A stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote attackers to execute arbitrary code by manipulating the 'delno' param...

Dec 28, 2025
CVE-2025-14187
7.2

A buffer overflow vulnerability in UGREEN DH2100+ NAS devices allows remote attackers to execute arbitrary code by manipulating the 'path' parameter i...

Dec 7, 2025
CVE-2025-20053
7.2

A buffer restriction vulnerability in Intel Xeon Processor firmware with SGX enabled allows privileged users to potentially escalate privileges via lo...

Aug 12, 2025
CVE-2025-4883
7.2

A critical stack-based buffer overflow vulnerability in D-Link DI-8100 routers allows remote attackers to execute arbitrary code by manipulating param...

May 18, 2025
CVE-2024-42442
7.2

CVE-2024-42442 is a memory buffer vulnerability in AMI APTIOV BIOS that allows network-based attackers to execute arbitrary code outside System Manage...

Nov 12, 2024
CVE-2022-48681
7.2

This CVE describes a memory overflow vulnerability in certain Huawei smart speakers. Successful exploitation could cause certain functions to fail, po...

May 28, 2024
CVE-2019-15992
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on Cisco ASA and FTD devices by exploiting ins...

Sep 23, 2020
CVE-2025-31219
7.1

This is a memory corruption vulnerability in Apple operating systems that could allow an attacker to cause system crashes or corrupt kernel memory. It...

May 12, 2025
CVE-2024-33258
7.1

CVE-2024-33258 is a memory corruption vulnerability in JerryScript's JavaScript engine that allows attackers to cause segmentation faults via speciall...

Apr 26, 2024
CVE-2024-27791
7.1

This vulnerability allows a malicious app to corrupt coprocessor memory on Apple devices, potentially leading to arbitrary code execution or system in...

Apr 24, 2024
CVE-2023-43815
7.1

A buffer overflow vulnerability in Delta Electronics DOPSoft version 2 allows remote code execution when parsing malicious DPS files. Attackers can ex...

Jan 18, 2024
CVE-2023-32436
7.1

This macOS kernel vulnerability allows malicious applications to bypass memory bounds checks, potentially causing system crashes or writing to kernel ...

Jan 10, 2024
CVE-2023-2977
7.1

This vulnerability in OpenSC allows attackers to trigger a heap-based buffer out-of-bounds read by sending a specially crafted smart card package with...

Jun 1, 2023
CVE-2021-31883
7.1

This vulnerability affects Siemens Capital Embedded AR Classic products where the DHCP client fails to validate vendor option lengths in DHCP ACK mess...

Nov 9, 2021
CVE-2021-3561
7.1

CVE-2021-3561 is an out-of-bounds memory access vulnerability in fig2dev's read_objects() function that allows attackers to crash the application or p...

May 26, 2021
CVE-2023-36747
7.0

CVE-2023-36747 is a heap-based buffer overflow vulnerability in GTKWave's FST file parser. Attackers can exploit this by tricking users into opening m...

Jan 8, 2024
CVE-2023-28638
7.0

Snappier 1.1.0 contains a buffer overrun vulnerability due to byte references briefly pointing outside valid buffer areas during garbage collection co...

Mar 27, 2023
CVE-2020-25599
7.0

A race condition vulnerability in Xen's event channel reset mechanism allows x86 PV guests to potentially escalate privileges to host level, cause hos...

Sep 23, 2020
CVE-2025-26503
6.7

This vulnerability allows an attacker to cause memory corruption by providing a crafted argument to a system call. This affects systems running vulner...

Sep 18, 2025
CVE-2023-1073
6.6

A memory corruption vulnerability in the Linux kernel's HID subsystem allows local attackers to crash the system or potentially escalate privileges by...

Mar 27, 2023
CVE-2026-20644
6.5

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It af...

Feb 11, 2026
CVE-2026-20636
6.5

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It af...

Feb 11, 2026
CVE-2026-21634
6.5

An attacker on the same network can crash the UniFi Protect Application by sending specially crafted discovery protocol packets. This affects all UniF...

Jan 5, 2026
CVE-2025-11683
6.5

YAML::Syck versions before 1.36 for Perl have a missing null-terminator vulnerability in token.c that causes out-of-bounds reads when processing compl...

Oct 16, 2025
CVE-2025-43212
6.5

A memory handling vulnerability in Apple WebKit (CWE-119) allows malicious web content to cause Safari to crash unexpectedly. This affects users of Sa...

Jul 30, 2025
CVE-2025-43214
6.5

This CVE describes a memory handling vulnerability in Apple's Safari browser and related WebKit components across multiple Apple operating systems. Pr...

Jul 30, 2025
CVE-2025-24132
6.5

This memory handling vulnerability in Apple's AirPlay and CarPlay SDKs allows attackers on the same local network to cause application crashes through...

Apr 30, 2025
CVE-2025-29492
6.5

CVE-2025-29492 is a memory corruption vulnerability in libming v0.4.8 that causes a segmentation fault in the decompileSETVARIABLE function. This vuln...

Mar 27, 2025
CVE-2025-29494
6.5

CVE-2025-29494 is a memory corruption vulnerability in libming v0.4.8's decompileGETMEMBER function that causes a segmentation fault when processing m...

Mar 27, 2025
CVE-2025-29485
6.5

CVE-2025-29485 is a memory corruption vulnerability in libming v0.4.8 that causes a segmentation fault when processing specially crafted SWF files. At...

Mar 27, 2025
CVE-2025-1896
6.5

A critical buffer overflow vulnerability in Tenda TX3 routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...

Mar 4, 2025
CVE-2025-1898
6.5

A critical buffer overflow vulnerability in Tenda TX3 routers allows remote attackers to execute arbitrary code by manipulating the schedStartTime/sch...

Mar 4, 2025
CVE-2025-0570
6.5

This vulnerability allows authenticated remote attackers to cause denial-of-service conditions on Sante PACS Server installations by sending specially...

Jan 30, 2025
CVE-2025-0848
6.5

A critical stack-based buffer overflow vulnerability in Tenda A18 routers allows remote attackers to execute arbitrary code by sending specially craft...

Jan 30, 2025
CVE-2024-10498
6.5

This CVE describes a buffer overflow vulnerability in Schneider Electric devices that allows unauthorized attackers to send malicious Modbus write pac...

Jan 17, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,224 CVEs classified as CWE-119, with 144 rated critical and 889 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free