CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,154
Total CVEs
119
Critical
846
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Linksys 22

All Buffer Overflow CVEs (1,154)

CVE-2026-2871
8.8

CVE-2026-2871 is a remote stack-based buffer overflow vulnerability in Tenda A21 routers. Attackers can exploit this to execute arbitrary code or cras...

Feb 21, 2026
CVE-2026-2870
8.8

A stack-based buffer overflow vulnerability in Tenda A21 routers allows remote attackers to execute arbitrary code by manipulating the QoS configurati...

Feb 21, 2026
CVE-2026-2857
8.8

A stack-based buffer overflow vulnerability in the D-Link DWR-M960 router's port forwarding configuration endpoint allows remote attackers to execute ...

Feb 20, 2026
CVE-2026-2853
8.8

A stack-based buffer overflow vulnerability in D-Link DWR-M960 routers allows remote attackers to execute arbitrary code by manipulating the submit-ur...

Feb 20, 2026
CVE-2026-2855
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DWR-M960 routers through a stack-based buffer overflow in the DDNS sett...

Feb 20, 2026
CVE-2026-2202
8.8

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the shareSpeed parameter in the...

Feb 9, 2026
CVE-2026-2203
8.8

A buffer overflow vulnerability exists in Tenda AC8 routers version 16.03.33.05. Remote attackers can exploit this by sending specially crafted reques...

Feb 9, 2026
CVE-2026-2185
8.8

A stack-based buffer overflow vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code by manipulating device name paramet...

Feb 8, 2026
CVE-2026-2186
8.8

This vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetIpMacBind fu...

Feb 8, 2026
CVE-2026-2187
8.8

This CVE describes a stack-based buffer overflow vulnerability in Tenda RX3 routers. Attackers can remotely exploit this vulnerability by manipulating...

Feb 8, 2026
CVE-2026-2180
8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 routers version 16.03.13.11. Attackers can remotely exploit this by manipulating the s...

Feb 8, 2026
CVE-2026-2181
8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 router firmware version 16.03.13.11. Attackers can remotely exploit this by manipulati...

Feb 8, 2026
CVE-2026-2140
8.8

A buffer overflow vulnerability exists in Tenda TX9 routers through firmware version 22.03.02.10_multi. Attackers can remotely exploit this vulnerabil...

Feb 8, 2026
CVE-2026-2139
8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the ssid parameter in the fast_...

Feb 8, 2026
CVE-2026-2138
8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the list argument in the SetSta...

Feb 8, 2026
CVE-2026-2137
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda TX3 routers via a buffer overflow in the SetIpMacBind function. Attacker...

Feb 8, 2026
CVE-2026-2086
8.8

A buffer overflow vulnerability in the UTT HiPER 810G firewall's management interface allows remote attackers to execute arbitrary code or crash the d...

Feb 7, 2026
CVE-2026-2071
8.8

A buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploiting the s...

Feb 7, 2026
CVE-2026-2070
8.8

A buffer overflow vulnerability in UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploitin...

Feb 6, 2026
CVE-2026-2068
8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627. Attackers can exploit this by sending spec...

Feb 6, 2026
CVE-2026-2066
8.8

A buffer overflow vulnerability exists in the UTT 进取 520W router firmware version 1.7.7-180627, specifically in the formIpGroupConfig function. At...

Feb 6, 2026
CVE-2026-2067
8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by manip...

Feb 6, 2026
CVE-2026-1686
8.8

A remote buffer overflow vulnerability in Totolink A3600R routers allows attackers to execute arbitrary code by manipulating the apcliSsid parameter i...

Jan 30, 2026
CVE-2026-1637
8.8

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC21 routers running firmware version 16.03.08.16. Attackers can remotely expl...

Jan 29, 2026
CVE-2026-1420
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC23 routers via a buffer overflow in the WifiExtraSet function. Attacke...

Jan 26, 2026
CVE-2026-1329
8.8

A stack-based buffer overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by manipulating parameters in th...

Jan 22, 2026
CVE-2026-1328
8.8

A buffer overflow vulnerability in Totolink NR1800X routers allows remote attackers to execute arbitrary code by sending specially crafted POST reques...

Jan 22, 2026
CVE-2026-1158
8.8

A remote buffer overflow vulnerability in Totolink LR350 routers allows attackers to execute arbitrary code by sending specially crafted POST requests...

Jan 19, 2026
CVE-2026-1157
8.8

A buffer overflow vulnerability in the Totolink LR350 router's WiFi configuration function allows remote attackers to execute arbitrary code. This aff...

Jan 19, 2026
CVE-2026-1156
8.8

A buffer overflow vulnerability in Totolink LR350 routers allows remote attackers to execute arbitrary code by manipulating the ssid parameter in the ...

Jan 19, 2026
CVE-2026-1140
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 520W routers by exploiting a buffer overflow in the ConfigExceptAli...

Jan 19, 2026
CVE-2026-1138
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 520W routers through a buffer overflow in the ConfigExceptQQ functi...

Jan 19, 2026
CVE-2026-1139
8.8

A buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code or cause denial of ...

Jan 19, 2026
CVE-2026-1137
8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware allows remote attackers to execute arbitrary code via the strcpy function in th...

Jan 19, 2026
CVE-2026-0841
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 520W routers running version 1.7.7-180627. Attackers can exploit a ...

Jan 11, 2026
CVE-2026-0840
8.8

This is a remote buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627. Attackers can exploit the strcpy function ...

Jan 11, 2026
CVE-2026-0838
8.8

This is a remote buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627 that allows attackers to execute arbitrary code by man...

Jan 11, 2026
CVE-2026-0839
8.8

This is a remote buffer overflow vulnerability in UTT 进取 520W router firmware version 1.7.7-180627. Attackers can exploit the strcpy function in t...

Jan 11, 2026
CVE-2026-0837
8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by explo...

Jan 11, 2026
CVE-2026-0836
8.8

This CVE describes a buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627. Attackers can remotely exploit this vu...

Jan 11, 2026
CVE-2026-0640
8.8

A buffer overflow vulnerability in Tenda AC23 routers allows remote attackers to execute arbitrary code by manipulating the Time parameter in the Powe...

Jan 6, 2026
CVE-2025-15462
8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware allows remote attackers to execute arbitrary code by exploiting the strcpy func...

Jan 5, 2026
CVE-2025-15461
8.8

This vulnerability is a buffer overflow in the UTT 进取 520W router firmware version 1.7.7-180627, specifically in the strcpy function handling the ...

Jan 5, 2026
CVE-2025-15459
8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by explo...

Jan 5, 2026
CVE-2025-15460
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 520W routers by exploiting a buffer overflow in the strcpy function...

Jan 5, 2026
CVE-2025-15431
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices via a buffer overflow in the FTP server configuration ...

Jan 2, 2026
CVE-2025-15429
8.8

A remote buffer overflow vulnerability in UTT 进取 512W firmware version 1.7.7-171114 allows attackers to execute arbitrary code or cause denial of ...

Jan 2, 2026
CVE-2025-15428
8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 512W router firmware version 1.7.7-171114. Attackers can exploit the strcpy fu...

Jan 2, 2026
CVE-2025-15356
8.8

A buffer overflow vulnerability in Tenda AC20 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the P...

Dec 30, 2025
CVE-2025-15234
8.8

This CVE describes a heap-based buffer overflow vulnerability in Tenda M3 routers version 1.0.0.13(4903). Attackers can remotely exploit this vulnerab...

Dec 30, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,154 CVEs classified as CWE-119, with 119 rated critical and 846 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free