CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,231
Total CVEs
144
Critical
896
High
8.0
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
185
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 49
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Fedoraproject 26
9 Freefloat 25
10 Cisco 25

All Buffer Overflow CVEs (1,231)

CVE-2025-8843
5.3

A heap-based buffer overflow vulnerability in NASM Netwide Assembler 2.17rc0 allows attackers with local access to potentially execute arbitrary code ...

Aug 11, 2025
CVE-2025-8842
5.3

A use-after-free vulnerability in NASM Netwide Assembler 2.17rc0 allows local attackers to potentially execute arbitrary code or cause denial of servi...

Aug 11, 2025
CVE-2025-8837
5.3

This CVE describes a use-after-free vulnerability in JasPer's JPEG2000 file handler that could allow local attackers to execute arbitrary code or caus...

Aug 11, 2025
CVE-2025-8736
5.3

A critical buffer overflow vulnerability exists in GNU cflow's lexer component (yylex function in c.c) affecting versions up to 1.8. This allows local...

Aug 8, 2025
CVE-2025-8585
5.3

A critical double-free vulnerability in libav's DSS File Demuxer component allows local attackers to potentially execute arbitrary code or cause denia...

Aug 5, 2025
CVE-2025-8176
5.3

A critical use-after-free vulnerability in LibTIFF's tiffmedian tool allows local attackers to execute arbitrary code or cause denial of service. This...

Jul 26, 2025
CVE-2025-7546
5.3

This vulnerability in GNU Binutils 2.45 allows an attacker to trigger an out-of-bounds write in the bfd_elf_set_group_contents function. Attackers wit...

Jul 13, 2025
CVE-2025-5898
5.3

A critical out-of-bounds write vulnerability in GNU PSPP's parse_variables_option function allows local attackers to execute arbitrary code or crash t...

Jun 9, 2025
CVE-2025-5297
5.3

A critical stack-based buffer overflow vulnerability exists in SourceCodester Computer Store System 1.0's main.c file. Attackers with local access can...

May 28, 2025
CVE-2025-4891
5.3

A critical buffer overflow vulnerability exists in the Police Station Management System 1.0, specifically in the criminal record display function. Att...

May 18, 2025
CVE-2025-4889
5.3

A critical buffer overflow vulnerability exists in the Tourism Management System 1.0 User Registration component. Attackers with local access can expl...

May 18, 2025
CVE-2025-4501
5.3

A critical stack-based buffer overflow vulnerability exists in the Album Management System 1.0 searchalbum function. This allows local attackers to ex...

May 10, 2025
CVE-2025-4499
5.3

A critical stack-based buffer overflow vulnerability exists in Simple Hospital Management System 1.0. Attackers with local access can exploit this by ...

May 10, 2025
CVE-2025-4497
5.3

A critical buffer overflow vulnerability exists in the Simple Banking System's sign-in component when processing the password2 argument. This allows l...

May 10, 2025
CVE-2025-4068
5.3

A critical stack-based buffer overflow vulnerability exists in the changeprize function of Simple Movie Ticket Booking System 1.0. This allows local a...

Apr 29, 2025
CVE-2025-4062
5.3

A stack-based buffer overflow vulnerability exists in the Theater Seat Booking System 1.0's cancel function when processing the cancelcustomername arg...

Apr 29, 2025
CVE-2025-3588
5.3

A stack-based buffer overflow vulnerability exists in jsonschema2pojo 1.2.2's JSON file handler when processing malicious JSON schemas. This allows lo...

Apr 14, 2025
CVE-2025-3548
5.3

This critical vulnerability in Open Asset Import Library (Assimp) allows heap-based buffer overflow via the aiString::Set function when processing mal...

Apr 14, 2025
CVE-2025-3166
5.3

A critical stack-based buffer overflow vulnerability exists in code-projects Product Management System 1.0's search_item function. Attackers with loca...

Apr 3, 2025
CVE-2025-3158
5.3

A critical heap-based buffer overflow vulnerability exists in Assimp's LWO file handler. Attackers can exploit this by crafting malicious LWO files to...

Apr 3, 2025
CVE-2025-3139
5.3

A critical buffer overflow vulnerability exists in the Bus Reservation System 1.0 login function. Attackers can exploit this by manipulating the Str1 ...

Apr 3, 2025
CVE-2024-13941
5.3

This is a critical memory corruption vulnerability in the ouch archive utility's ZIP date-time parsing function. Attackers with local access can explo...

Apr 1, 2025
CVE-2025-3001
5.3

A critical memory corruption vulnerability in PyTorch's torch.lstm_cell function allows local attackers to potentially execute arbitrary code or crash...

Mar 31, 2025
CVE-2025-2309
5.3

A critical heap-based buffer overflow vulnerability in HDF5 library's type conversion logic allows attackers with local access to potentially execute ...

Mar 14, 2025
CVE-2025-1372
5.3

A critical buffer overflow vulnerability in GNU elfutils' eu-readelf tool allows local attackers to execute arbitrary code or cause denial of service ...

Feb 17, 2025
CVE-2025-1367
5.3

A critical buffer overflow vulnerability exists in MicroWord eScan Antivirus 7.0.32 on Linux within the USB Password Handler component. This allows lo...

Feb 17, 2025
CVE-2025-1365
5.3

A critical buffer overflow vulnerability in GNU elfutils' eu-readelf component allows local attackers to execute arbitrary code or cause denial of ser...

Feb 17, 2025
CVE-2025-1364
5.3

A critical stack-based buffer overflow vulnerability in MicroWord eScan Antivirus 7.0.32 on Linux allows local attackers to execute arbitrary code via...

Feb 16, 2025
CVE-2025-1163
5.3

A critical stack-based buffer overflow vulnerability exists in the Vehicle Parking Management System 1.0 login function. Attackers with local access c...

Feb 11, 2025
CVE-2025-0529
5.3

A critical stack-based buffer overflow vulnerability exists in the Train Ticket Reservation System 1.0 login form. Attackers can exploit this by manip...

Jan 17, 2025
CVE-2024-12354
5.3

A critical buffer overflow vulnerability in SourceCodester Phone Contact Manager System 1.0 allows attackers to execute arbitrary code or crash the sy...

Dec 9, 2024
CVE-2024-12186
5.3

A stack-based buffer overflow vulnerability exists in the Hotel Management System 1.0's Available Room Handler component. Local attackers can exploit ...

Dec 5, 2024
CVE-2024-45809
5.3

A vulnerability in Envoy's JWT filter causes a crash when specific conditions are met: remote JWKs are used with clear_route_cache enabled, header ope...

Sep 20, 2024
CVE-2023-1679
5.3

This is a critical local privilege escalation vulnerability in DriverGenius software. The vulnerability allows attackers with local access to exploit ...

Mar 28, 2023
CVE-2023-1626
5.3

This is a critical local privilege escalation vulnerability in Jianming Antivirus 16.2.2022.418. The vulnerability exists in the kvcore.sys driver's I...

Mar 25, 2023
CVE-2025-1352
5.0

A critical memory corruption vulnerability in GNU elfutils' eu-readelf component allows remote attackers to potentially execute arbitrary code or caus...

Feb 16, 2025
CVE-2025-1182
5.0

A critical memory corruption vulnerability in GNU Binutils' linker (ld) allows remote attackers to potentially execute arbitrary code or cause denial ...

Feb 11, 2025
CVE-2025-1181
5.0

A critical memory corruption vulnerability in GNU Binutils' linker component (ld) allows remote attackers to potentially execute arbitrary code or cau...

Feb 11, 2025
CVE-2025-1176
5.0

A critical heap-based buffer overflow vulnerability in GNU Binutils' linker component (ld) allows remote attackers to potentially execute arbitrary co...

Feb 11, 2025
CVE-2025-0840
5.0

A stack-based buffer overflow vulnerability exists in GNU Binutils' objdump tool when processing specially crafted input. This could allow remote atta...

Jan 29, 2025
CVE-2025-43504
4.9

A buffer overflow vulnerability in Xcode allows attackers in privileged network positions to cause denial-of-service conditions. This affects develope...

Nov 4, 2025
CVE-2024-38269
4.9

This vulnerability allows authenticated attackers with administrator privileges to cause memory corruption in the USB file-sharing handler of Zyxel VM...

Sep 24, 2024
CVE-2024-38267
4.9

This vulnerability allows authenticated administrators to cause memory corruption in the IPv6 parser of Zyxel VMG8825-T50K devices, potentially crashi...

Sep 24, 2024
CVE-2025-62594
4.7

ImageMagick versions before 7.1.2-8 contain a vulnerability in the CLAHEImage function where zero tile dimensions cause unsigned integer underflow and...

Oct 27, 2025
CVE-2025-31257
4.7

This CVE describes a memory handling vulnerability in Apple's WebKit browser engine that could cause Safari to crash when processing malicious web con...

May 12, 2025
CVE-2026-20605
4.6

This memory handling vulnerability in Apple operating systems allows malicious applications to crash system processes. It affects macOS, iOS, and iPad...

Feb 11, 2026
CVE-2025-11947
4.5

A heap-based buffer overflow vulnerability exists in bftpd's configuration file handler when processing group expansions. This allows local attackers ...

Oct 19, 2025
CVE-2025-9020
4.5

This CVE describes a use-after-free vulnerability in PX4 Autopilot's Mavlink Shell Closing Handler component. An attacker with local access could pote...

Aug 15, 2025
CVE-2024-4162
4.4

A buffer error vulnerability in Panasonic KW Watcher versions 1.00 through 2.83 allows attackers to read arbitrary memory contents. This affects users...

May 8, 2024
CVE-2023-21044
4.4

This vulnerability allows local information disclosure on Android devices through an out-of-bounds read in the VendorGraphicBufferMeta initialization....

Mar 24, 2023

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,231 CVEs classified as CWE-119, with 144 rated critical and 896 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free