CWE-119: Buffer Overflow
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Yearly Trend
Top Affected Vendors
All Buffer Overflow CVEs (1,228)
This CVE describes an out-of-bounds write vulnerability in GPAC's SRT subtitle import function. Attackers with local access can exploit this to potent...
Jan 26, 2026A heap-based buffer overflow vulnerability exists in Mapnik's shapefile input plugin, specifically in the dbf_file::string_value function. This allows...
Jan 18, 2026A heap-based buffer overflow vulnerability exists in BYVoid OpenCC versions up to 1.1.9, specifically in the MaxMatchSegmentation function. This allow...
Jan 18, 2026A buffer overflow vulnerability exists in the rtsp_parse_method function of cijliu librtsp, allowing local attackers to potentially execute arbitrary ...
Jan 18, 2026A heap-based buffer overflow vulnerability exists in raylib's GenImageFontAtlas function. This allows local attackers to execute arbitrary code or cau...
Jan 18, 2026A buffer overflow vulnerability exists in the rtsp_parse_request function of cijliu librtsp, allowing local attackers to potentially execute arbitrary...
Jan 18, 2026A buffer overflow vulnerability exists in the rtsp_rely_dumps function of cijliu librtsp, allowing local attackers to potentially execute arbitrary co...
Jan 18, 2026A memory corruption vulnerability in Firefox and Thunderbird's graphics component due to incorrect boundary conditions. This could allow attackers to ...
Jan 13, 2026An out-of-bounds read vulnerability in wabt's wasm-decompile tool allows local attackers to read memory beyond intended boundaries. This affects users...
Jan 1, 2026A memory corruption vulnerability in wasm3 up to version 0.5.0 allows local attackers to potentially execute arbitrary code or cause denial of service...
Jan 1, 2026A stack-based buffer overflow vulnerability exists in the _sg_pipeline_desc_defaults function of floooh sokol's sokol_gfx.h library. This allows local...
Dec 28, 2025This CVE describes a stack-based buffer overflow vulnerability in PX4 Autopilot's MavlinkLogHandler component. Attackers with local access can potenti...
Dec 28, 2025A stack-based buffer overflow vulnerability exists in the _sg_validate_pipeline_desc function of floooh sokol's sokol_gfx.h library. This allows local...
Dec 22, 2025This CVE describes a heap-based buffer overflow vulnerability in WebAssembly Binaryen's WasmBinaryReader::readExport function. Attackers can exploit t...
Dec 19, 2025A use-after-free vulnerability in whisper.cpp's read_audio_data function allows local attackers to potentially execute arbitrary code or crash the app...
Dec 12, 2025A buffer overflow vulnerability in Samsung Exynos processors allows attackers to cause a fatal error by sending malformed SOR transparent container da...
Dec 3, 2025This CVE describes a use-after-free vulnerability in mruby's sort_cmp function that could allow local attackers to execute arbitrary code or cause den...
Nov 13, 2025This CVE describes an out-of-bounds write vulnerability in mruby 3.4.0's array handling function. Attackers with local access can manipulate arguments...
Nov 7, 2025A buffer over-read vulnerability in QuickJS's js_array_buffer_slice function allows reading beyond allocated memory boundaries. This affects QuickJS u...
Nov 5, 2025A heap-based buffer overflow vulnerability exists in Kamailio's configuration file handler when processing malicious config files. This allows local a...
Oct 27, 2025A use-after-free vulnerability in Kamailio's configuration file parser allows local attackers to potentially crash the service or execute arbitrary co...
Oct 27, 2025This CVE describes a stack-based buffer overflow vulnerability in DCMTK's dcmqrscp component. Attackers with local access can exploit the parseQuota f...
Oct 21, 2025A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's Q3D file parser. Attackers with local access can execute arbitrary code by providi...
Oct 5, 2025A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's ODDLParser::getNextSeparator function. This allows local attackers to potentially ...
Oct 5, 2025A heap-based buffer overflow vulnerability in GNU Binutils' linker component allows local attackers to execute arbitrary code or cause denial of servi...
Sep 27, 2025A heap-based buffer overflow vulnerability in GNU Binutils' linker component allows local attackers to execute arbitrary code or cause denial of servi...
Sep 27, 2025A memory management vulnerability in OGRECave Ogre's STBIImageCodec::encode function allows local attackers to potentially execute arbitrary code or c...
Sep 26, 2025A heap-based buffer overflow vulnerability exists in OGRECave Ogre's STBIImageCodec::encode function, allowing local attackers to execute arbitrary co...
Sep 26, 2025A stack-based buffer overflow vulnerability exists in BehaviorTree up to version 4.7.0, specifically in the ParseScript function of the Diagnostic Mes...
Sep 26, 2025A heap-based buffer overflow vulnerability in vstakhov libucl up to version 0.9.2 allows local attackers to potentially execute arbitrary code or caus...
Sep 26, 2025A heap-based buffer overflow vulnerability exists in Open Babel versions up to 3.1.1, specifically in the ChemKinFormat::CheckSpecies function. This a...
Sep 26, 2025This vulnerability allows local attackers to execute arbitrary code or cause denial of service through a heap-based buffer overflow in Open Babel's SM...
Sep 26, 2025CVE-2025-10994 is a use-after-free vulnerability in Open Babel's GAMESS file parser that could allow local attackers to execute arbitrary code or caus...
Sep 26, 2025A memory corruption vulnerability in Open Babel's zlib decompression stream allows local attackers to potentially execute arbitrary code or cause deni...
Sep 26, 2025A use-after-free vulnerability in axboe fio's __parse_jobs_ini function allows local attackers to potentially execute arbitrary code or cause denial o...
Sep 23, 2025This CVE describes an AMD IOMMU vulnerability where a malicious hypervisor could improperly access guest virtual machine memory. This affects AMD proc...
Sep 6, 2025A memory corruption vulnerability in DCMTK's dcm2img component allows local attackers to potentially crash applications or execute arbitrary code. Thi...
Aug 31, 2025A use-after-free vulnerability in PoDoFo's PDF dictionary parser allows local attackers to potentially execute arbitrary code or cause denial of servi...
Aug 24, 2025A buffer overflow vulnerability in vim's xxd component allows local attackers to execute arbitrary code or cause denial of service. The flaw exists in...
Aug 24, 2025CVE-2025-9386 is a use-after-free vulnerability in tcpreplay's tcprewrite component that allows local attackers to potentially execute arbitrary code ...
Aug 24, 2025A use-after-free vulnerability in tcpreplay's tcprewrite component allows local attackers to potentially crash the application or execute arbitrary co...
Aug 24, 2025A stack-based buffer overflow vulnerability in neurobin shc up to version 4.0.3 allows local attackers to execute arbitrary code or cause denial of se...
Aug 19, 2025A use-after-free vulnerability in tcpreplay's tcprewrite component allows local attackers to execute arbitrary code or cause denial of service. The vu...
Aug 19, 2025CVE-2025-9136 is an out-of-bounds read vulnerability in RetroArch's filestream_vscanf function that could allow local attackers to read sensitive memo...
Aug 19, 2025A stack-based buffer overflow vulnerability exists in LemonOS's HTTP client component. Attackers can remotely exploit this by manipulating chunkSize p...
Aug 15, 2025A stack-based buffer overflow vulnerability exists in LibTIFF's tiffcrop utility, specifically in the readSeparateStripsetoBuffer function. This vulne...
Aug 11, 2025A stack-based buffer overflow vulnerability exists in NASM Netwide Assembler 2.17rc0's parse_line function in parser.c. This allows local attackers to...
Aug 11, 2025A heap-based buffer overflow vulnerability in NASM Netwide Assembler 2.17rc0 allows attackers with local access to potentially execute arbitrary code ...
Aug 11, 2025A use-after-free vulnerability in NASM Netwide Assembler 2.17rc0 allows local attackers to potentially execute arbitrary code or cause denial of servi...
Aug 11, 2025This CVE describes a use-after-free vulnerability in JasPer's JPEG2000 file handler that could allow local attackers to execute arbitrary code or caus...
Aug 11, 2025About Buffer Overflow (CWE-119)
The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
Our database tracks 1,228 CVEs classified as CWE-119, with 144 rated critical and 893 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-119 on MITRE CWE →
Monitor Buffer Overflow Vulnerabilities
Get alerted when new Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free