CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,225
Total CVEs
144
Critical
890
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
180
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 26
9 Freefloat 25
10 Mozilla 24

All Buffer Overflow CVEs (1,225)

CVE-2024-10498
6.5

This CVE describes a buffer overflow vulnerability in Schneider Electric devices that allows unauthorized attackers to send malicious Modbus write pac...

Jan 17, 2025
CVE-2024-12343
6.5

A critical buffer overflow vulnerability in TP-Link VN020 F3v(T) routers allows attackers within the local network to execute arbitrary code or cause ...

Dec 8, 2024
CVE-2024-12147
6.5

A critical buffer overflow vulnerability in Netgear R6900 routers allows remote attackers to execute arbitrary code by manipulating the Content-Length...

Dec 4, 2024
CVE-2024-32761
6.5

This CVE describes a data leak vulnerability in F5 BIG-IP Traffic Management Microkernels (TMMs) running on VELOS and rSeries platforms. Under certain...

May 8, 2024
CVE-2026-3697
6.3

A stack-based buffer overflow vulnerability exists in Planet ICG-2510's web server language configuration handler. Remote attackers can exploit this b...

Mar 8, 2026
CVE-2026-2930
6.3

A stack-based buffer overflow vulnerability in Tenda A18 routers allows remote attackers to execute arbitrary code by manipulating the boundary argume...

Feb 22, 2026
CVE-2026-1144
6.3

This CVE describes a use-after-free vulnerability in quickjs-ng's Atomics Ops Handler component that can be exploited remotely. Attackers could potent...

Jan 19, 2026
CVE-2026-0822
6.3

A heap-based buffer overflow vulnerability in quickjs-ng's js_typed_array_sort function allows remote attackers to execute arbitrary code or cause den...

Jan 10, 2026
CVE-2025-14607
6.3

A memory corruption vulnerability in OFFIS DCMTK's DcmByteString::makeDicomByteString function allows remote attackers to potentially execute arbitrar...

Dec 13, 2025
CVE-2025-9362
6.3

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating URL...

Aug 23, 2025
CVE-2025-3407
6.3

This critical vulnerability in the stb library allows remote attackers to trigger an out-of-bounds read via manipulated h_count/v_count parameters in ...

Apr 8, 2025
CVE-2025-3015
6.3

This critical vulnerability in Assimp's ASE file handler allows remote attackers to trigger out-of-bounds memory reads by manipulating specially craft...

Mar 31, 2025
CVE-2025-2757
6.3

A critical heap-based buffer overflow vulnerability in Assimp's MD5 file parser allows remote attackers to execute arbitrary code or cause denial of s...

Mar 25, 2025
CVE-2025-2754
6.3

A critical heap-based buffer overflow vulnerability in Assimp's AC3D file handler allows remote attackers to execute arbitrary code or crash applicati...

Mar 25, 2025
CVE-2025-2357
6.3

A critical memory corruption vulnerability in DCMTK's JPEG-LS decoder allows remote attackers to potentially execute arbitrary code or crash applicati...

Mar 17, 2025
CVE-2025-2337
6.3

A critical heap-based buffer overflow vulnerability in matio library versions 1.5.28 allows remote attackers to execute arbitrary code or cause denial...

Mar 16, 2025
CVE-2025-2152
6.3

A critical heap-based buffer overflow vulnerability in Assimp's BaseImporter::ConvertToUTF8 function allows remote attackers to execute arbitrary code...

Mar 10, 2025
CVE-2025-2151
6.3

A critical stack-based buffer overflow vulnerability in Assimp's GetNextLine function allows remote attackers to execute arbitrary code or crash appli...

Mar 10, 2025
CVE-2025-0753
6.3

A critical heap-based buffer overflow vulnerability in Axiomatic Bento4's mp42aac component allows remote attackers to execute arbitrary code or cause...

Jan 27, 2025
CVE-2025-65396
6.1

A physical access vulnerability in Blurams Flare Camera allows attackers to hijack the boot process via UART interface by shorting SPI flash memory pi...

Jan 14, 2026
CVE-2023-31352
6.0

A vulnerability in AMD SEV firmware allows attackers with hypervisor privileges to read unencrypted guest memory, potentially exposing sensitive data....

Feb 11, 2025
CVE-2024-56438
6.0

This vulnerability in Huawei's HUKS (Hardware Unified Key Store) module allows improper memory address protection, potentially leading to denial of se...

Jan 8, 2025
CVE-2023-31355
6.0

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to overwrite a guest's UMC (Unified Memory Controller) see...

Aug 5, 2024
CVE-2025-46305
5.7

A buffer overflow vulnerability in macOS and iOS/iPadOS allows malicious USB HID devices to cause unexpected process crashes. This affects users of ma...

Feb 11, 2026
CVE-2025-46300
5.7

This vulnerability allows a malicious HID (Human Interface Device) to cause unexpected process crashes on affected Apple systems. It affects macOS, iO...

Feb 11, 2026
CVE-2025-46301
5.7

This vulnerability allows a malicious Human Interface Device (HID) like a keyboard or mouse to cause unexpected process crashes on affected Apple syst...

Feb 11, 2026
CVE-2025-46302
5.7

A buffer overflow vulnerability in macOS and iOS/iPadOS allows malicious HID devices to cause unexpected process crashes. This affects users of macOS ...

Feb 11, 2026
CVE-2025-46303
5.7

A buffer overflow vulnerability in macOS and iOS/iPadOS allows a malicious HID (Human Interface Device) to cause unexpected process crashes. This affe...

Feb 11, 2026
CVE-2026-1425
5.6

A stack-based buffer overflow vulnerability exists in pymumu SmartDNS versions up to 47.1, specifically in the SVCB/HTTPS record parser. This allows r...

Jan 26, 2026
CVE-2025-1178
5.6

A memory corruption vulnerability exists in GNU Binutils' bfd_putl64 function within the ld component. This allows remote attackers to potentially exe...

Feb 11, 2025
CVE-2026-20654
5.5

This memory handling vulnerability in Apple operating systems allows an app to cause unexpected system termination (kernel panic/crash). All users run...

Feb 11, 2026
CVE-2026-20621
5.5

This CVE describes a memory corruption vulnerability in Apple operating systems that allows an app to cause system crashes or corrupt kernel memory. I...

Feb 11, 2026
CVE-2025-14407
5.5

This vulnerability in Soda PDF Desktop allows remote attackers to disclose sensitive information by tricking users into opening malicious PDF files. T...

Dec 23, 2025
CVE-2025-43398
5.5

This memory handling vulnerability in Apple operating systems allows applications to cause unexpected system termination (kernel panic/crash). All use...

Nov 4, 2025
CVE-2025-7616
5.5

A critical memory corruption vulnerability exists in the pthread_cond_destroy function of gmg137 snap7-rs library versions up to 1.142.1. This vulnera...

Jul 14, 2025
CVE-2025-7208
5.5

A critical heap-based buffer overflow vulnerability exists in the edump function of plan9port's x509.c library. This allows attackers to execute arbit...

Jul 9, 2025
CVE-2025-6093
5.5

A critical stack-based buffer overflow vulnerability exists in the uYanki board-stm32f103rc-berial firmware's heartrate1_i2c_hal_write function. Attac...

Jun 15, 2025
CVE-2025-24111
5.5

This CVE describes a memory corruption vulnerability in Apple operating systems that could allow a malicious app to cause a system crash (unexpected t...

May 12, 2025
CVE-2025-3007
5.5

A critical stack-based buffer overflow vulnerability in Novastar CX40's NetFilter Utility allows attackers to execute arbitrary code or crash the syst...

Mar 31, 2025
CVE-2024-50248
5.5

This CVE addresses a memory bounds checking vulnerability in the NTFS3 filesystem driver in the Linux kernel. An attacker could potentially exploit th...

Nov 9, 2024
CVE-2022-48940
5.5

A memory corruption vulnerability in the Linux kernel's BPF subsystem allows local attackers to crash the kernel or potentially escalate privileges. T...

Aug 22, 2024
CVE-2021-47367
5.5

This vulnerability in the Linux kernel's virtio-net driver causes memory pages to leak when building network packets in 'big mode'. This allows attack...

May 21, 2024
CVE-2026-3731
5.3

CVE-2026-3731 is an out-of-bounds read vulnerability in libssh's SFTP extension handler that allows remote attackers to read memory beyond allocated b...

Mar 8, 2026
CVE-2026-3147
5.3

A heap-based buffer overflow vulnerability in libvips' CSV loading function allows local attackers to potentially execute arbitrary code or crash appl...

Feb 25, 2026
CVE-2026-2522
5.3

A memory corruption vulnerability in Open5GS MME component allows remote attackers to potentially crash the service or execute arbitrary code. This af...

Feb 16, 2026
CVE-2026-2016
5.3

A stack-based buffer overflow vulnerability exists in libfastcommon's base64_decode function, allowing local attackers to execute arbitrary code or ca...

Feb 6, 2026
CVE-2026-1979
5.3

A use-after-free vulnerability in mruby up to version 3.4.0 allows local attackers to execute arbitrary code or cause denial of service. This affects ...

Feb 6, 2026
CVE-2026-1418
5.3

This CVE describes an out-of-bounds write vulnerability in GPAC's SRT subtitle import function. Attackers with local access can exploit this to potent...

Jan 26, 2026
CVE-2025-15537
5.3

A heap-based buffer overflow vulnerability exists in Mapnik's shapefile input plugin, specifically in the dbf_file::string_value function. This allows...

Jan 18, 2026
CVE-2025-15536
5.3

A heap-based buffer overflow vulnerability exists in BYVoid OpenCC versions up to 1.1.9, specifically in the MaxMatchSegmentation function. This allow...

Jan 18, 2026

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,225 CVEs classified as CWE-119, with 144 rated critical and 890 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free