CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,228
Total CVEs
144
Critical
893
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
183
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 26
9 Freefloat 25
10 Mozilla 24

All Buffer Overflow CVEs (1,228)

CVE-2026-1418
5.3

This CVE describes an out-of-bounds write vulnerability in GPAC's SRT subtitle import function. Attackers with local access can exploit this to potent...

Jan 26, 2026
CVE-2025-15537
5.3

A heap-based buffer overflow vulnerability exists in Mapnik's shapefile input plugin, specifically in the dbf_file::string_value function. This allows...

Jan 18, 2026
CVE-2025-15536
5.3

A heap-based buffer overflow vulnerability exists in BYVoid OpenCC versions up to 1.1.9, specifically in the MaxMatchSegmentation function. This allow...

Jan 18, 2026
CVE-2026-1110
5.3

A buffer overflow vulnerability exists in the rtsp_parse_method function of cijliu librtsp, allowing local attackers to potentially execute arbitrary ...

Jan 18, 2026
CVE-2025-15533
5.3

A heap-based buffer overflow vulnerability exists in raylib's GenImageFontAtlas function. This allows local attackers to execute arbitrary code or cau...

Jan 18, 2026
CVE-2026-1109
5.3

A buffer overflow vulnerability exists in the rtsp_parse_request function of cijliu librtsp, allowing local attackers to potentially execute arbitrary...

Jan 18, 2026
CVE-2026-1108
5.3

A buffer overflow vulnerability exists in the rtsp_rely_dumps function of cijliu librtsp, allowing local attackers to potentially execute arbitrary co...

Jan 18, 2026
CVE-2026-0886
5.3

A memory corruption vulnerability in Firefox and Thunderbird's graphics component due to incorrect boundary conditions. This could allow attackers to ...

Jan 13, 2026
CVE-2025-15412
5.3

An out-of-bounds read vulnerability in wabt's wasm-decompile tool allows local attackers to read memory beyond intended boundaries. This affects users...

Jan 1, 2026
CVE-2025-15413
5.3

A memory corruption vulnerability in wasm3 up to version 0.5.0 allows local attackers to potentially execute arbitrary code or cause denial of service...

Jan 1, 2026
CVE-2025-15155
5.3

A stack-based buffer overflow vulnerability exists in the _sg_pipeline_desc_defaults function of floooh sokol's sokol_gfx.h library. This allows local...

Dec 28, 2025
CVE-2025-15150
5.3

This CVE describes a stack-based buffer overflow vulnerability in PX4 Autopilot's MavlinkLogHandler component. Attackers with local access can potenti...

Dec 28, 2025
CVE-2025-15013
5.3

A stack-based buffer overflow vulnerability exists in the _sg_validate_pipeline_desc function of floooh sokol's sokol_gfx.h library. This allows local...

Dec 22, 2025
CVE-2025-14956
5.3

This CVE describes a heap-based buffer overflow vulnerability in WebAssembly Binaryen's WasmBinaryReader::readExport function. Attackers can exploit t...

Dec 19, 2025
CVE-2025-14569
5.3

A use-after-free vulnerability in whisper.cpp's read_audio_data function allows local attackers to potentially execute arbitrary code or crash the app...

Dec 12, 2025
CVE-2025-53965
5.3

A buffer overflow vulnerability in Samsung Exynos processors allows attackers to cause a fatal error by sending malformed SOR transparent container da...

Dec 3, 2025
CVE-2025-13120
5.3

This CVE describes a use-after-free vulnerability in mruby's sort_cmp function that could allow local attackers to execute arbitrary code or cause den...

Nov 13, 2025
CVE-2025-12875
5.3

This CVE describes an out-of-bounds write vulnerability in mruby 3.4.0's array handling function. Attackers with local access can manipulate arguments...

Nov 7, 2025
CVE-2025-12745
5.3

A buffer over-read vulnerability in QuickJS's js_array_buffer_slice function allows reading beyond allocated memory boundaries. This affects QuickJS u...

Nov 5, 2025
CVE-2025-12204
5.3

A heap-based buffer overflow vulnerability exists in Kamailio's configuration file handler when processing malicious config files. This allows local a...

Oct 27, 2025
CVE-2025-12205
5.3

A use-after-free vulnerability in Kamailio's configuration file parser allows local attackers to potentially crash the service or execute arbitrary co...

Oct 27, 2025
CVE-2020-36855
5.3

This CVE describes a stack-based buffer overflow vulnerability in DCMTK's dcmqrscp component. Attackers with local access can exploit the parseQuota f...

Oct 21, 2025
CVE-2025-11277
5.3

A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's Q3D file parser. Attackers with local access can execute arbitrary code by providi...

Oct 5, 2025
CVE-2025-11275
5.3

A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's ODDLParser::getNextSeparator function. This allows local attackers to potentially ...

Oct 5, 2025
CVE-2025-11083
5.3

A heap-based buffer overflow vulnerability in GNU Binutils' linker component allows local attackers to execute arbitrary code or cause denial of servi...

Sep 27, 2025
CVE-2025-11082
5.3

A heap-based buffer overflow vulnerability in GNU Binutils' linker component allows local attackers to execute arbitrary code or cause denial of servi...

Sep 27, 2025
CVE-2025-11015
5.3

A memory management vulnerability in OGRECave Ogre's STBIImageCodec::encode function allows local attackers to potentially execute arbitrary code or c...

Sep 26, 2025
CVE-2025-11014
5.3

A heap-based buffer overflow vulnerability exists in OGRECave Ogre's STBIImageCodec::encode function, allowing local attackers to execute arbitrary co...

Sep 26, 2025
CVE-2025-11012
5.3

A stack-based buffer overflow vulnerability exists in BehaviorTree up to version 4.7.0, specifically in the ParseScript function of the Diagnostic Mes...

Sep 26, 2025
CVE-2025-11010
5.3

A heap-based buffer overflow vulnerability in vstakhov libucl up to version 0.9.2 allows local attackers to potentially execute arbitrary code or caus...

Sep 26, 2025
CVE-2025-10997
5.3

A heap-based buffer overflow vulnerability exists in Open Babel versions up to 3.1.1, specifically in the ChemKinFormat::CheckSpecies function. This a...

Sep 26, 2025
CVE-2025-10996
5.3

This vulnerability allows local attackers to execute arbitrary code or cause denial of service through a heap-based buffer overflow in Open Babel's SM...

Sep 26, 2025
CVE-2025-10994
5.3

CVE-2025-10994 is a use-after-free vulnerability in Open Babel's GAMESS file parser that could allow local attackers to execute arbitrary code or caus...

Sep 26, 2025
CVE-2025-10995
5.3

A memory corruption vulnerability in Open Babel's zlib decompression stream allows local attackers to potentially execute arbitrary code or cause deni...

Sep 26, 2025
CVE-2025-10824
5.3

A use-after-free vulnerability in axboe fio's __parse_jobs_ini function allows local attackers to potentially execute arbitrary code or cause denial o...

Sep 23, 2025
CVE-2023-31351
5.3

This CVE describes an AMD IOMMU vulnerability where a malicious hypervisor could improperly access guest virtual machine memory. This affects AMD proc...

Sep 6, 2025
CVE-2025-9732
5.3

A memory corruption vulnerability in DCMTK's dcm2img component allows local attackers to potentially crash applications or execute arbitrary code. Thi...

Aug 31, 2025
CVE-2025-9394
5.3

A use-after-free vulnerability in PoDoFo's PDF dictionary parser allows local attackers to potentially execute arbitrary code or cause denial of servi...

Aug 24, 2025
CVE-2025-9390
5.3

A buffer overflow vulnerability in vim's xxd component allows local attackers to execute arbitrary code or cause denial of service. The flaw exists in...

Aug 24, 2025
CVE-2025-9386
5.3

CVE-2025-9386 is a use-after-free vulnerability in tcpreplay's tcprewrite component that allows local attackers to potentially execute arbitrary code ...

Aug 24, 2025
CVE-2025-9385
5.3

A use-after-free vulnerability in tcpreplay's tcprewrite component allows local attackers to potentially crash the application or execute arbitrary co...

Aug 24, 2025
CVE-2025-9175
5.3

A stack-based buffer overflow vulnerability in neurobin shc up to version 4.0.3 allows local attackers to execute arbitrary code or cause denial of se...

Aug 19, 2025
CVE-2025-9157
5.3

A use-after-free vulnerability in tcpreplay's tcprewrite component allows local attackers to execute arbitrary code or cause denial of service. The vu...

Aug 19, 2025
CVE-2025-9136
5.3

CVE-2025-9136 is an out-of-bounds read vulnerability in RetroArch's filestream_vscanf function that could allow local attackers to read sensitive memo...

Aug 19, 2025
CVE-2025-9001
5.3

A stack-based buffer overflow vulnerability exists in LemonOS's HTTP client component. Attackers can remotely exploit this by manipulating chunkSize p...

Aug 15, 2025
CVE-2025-8851
5.3

A stack-based buffer overflow vulnerability exists in LibTIFF's tiffcrop utility, specifically in the readSeparateStripsetoBuffer function. This vulne...

Aug 11, 2025
CVE-2025-8846
5.3

A stack-based buffer overflow vulnerability exists in NASM Netwide Assembler 2.17rc0's parse_line function in parser.c. This allows local attackers to...

Aug 11, 2025
CVE-2025-8843
5.3

A heap-based buffer overflow vulnerability in NASM Netwide Assembler 2.17rc0 allows attackers with local access to potentially execute arbitrary code ...

Aug 11, 2025
CVE-2025-8842
5.3

A use-after-free vulnerability in NASM Netwide Assembler 2.17rc0 allows local attackers to potentially execute arbitrary code or cause denial of servi...

Aug 11, 2025
CVE-2025-8837
5.3

This CVE describes a use-after-free vulnerability in JasPer's JPEG2000 file handler that could allow local attackers to execute arbitrary code or caus...

Aug 11, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,228 CVEs classified as CWE-119, with 144 rated critical and 893 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free