CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,167
Total CVEs
124
Critical
854
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,167)

CVE-2025-12595
8.8

A buffer overflow vulnerability in Tenda AC23 routers allows remote attackers to execute arbitrary code by manipulating the argument list in the formS...

Nov 2, 2025
CVE-2025-12273
8.8

CVE-2025-12273 is a buffer overflow vulnerability in Tenda CH22 routers affecting version 1.0.0.1. Attackers can remotely exploit this by manipulating...

Oct 27, 2025
CVE-2025-12274
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'p...

Oct 27, 2025
CVE-2025-12271
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'p...

Oct 27, 2025
CVE-2025-12265
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'p...

Oct 27, 2025
CVE-2025-12258
8.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3300R routers by exploiting a stack-based buffer overflow in the set...

Oct 27, 2025
CVE-2025-12260
8.8

A stack-based buffer overflow vulnerability in TOTOLINK A3300R routers allows remote attackers to execute arbitrary code by manipulating the 'enable' ...

Oct 27, 2025
CVE-2025-12239
8.8

A remote buffer overflow vulnerability exists in TOTOLINK A3300R routers through the setDdnsCfg function in cstecgi.cgi. Attackers can exploit this to...

Oct 27, 2025
CVE-2025-12241
8.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3300R routers by exploiting a stack-based buffer overflow in the lan...

Oct 27, 2025
CVE-2025-12233
8.8

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fr...

Oct 27, 2025
CVE-2025-12236
8.8

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the DH...

Oct 27, 2025
CVE-2025-12225
8.8

This vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WifiGuestSet HTTP h...

Oct 27, 2025
CVE-2025-12213
8.8

A stack-based buffer overflow vulnerability in Tenda O3 routers allows remote attackers to execute arbitrary code by manipulating the 'lan' parameter ...

Oct 27, 2025
CVE-2025-12211
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda O3 routers via a stack-based buffer overflow in the DMZ configuration fu...

Oct 27, 2025
CVE-2025-12209
8.8

A stack-based buffer overflow vulnerability in Tenda O3 routers allows remote attackers to execute arbitrary code by manipulating the dhcpEn parameter...

Oct 27, 2025
CVE-2025-11715
8.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Oct 14, 2025
CVE-2025-11652
8.8

A buffer overflow vulnerability in UTT 进取 518G routers allows remote attackers to execute arbitrary code by manipulating the txtMin2 parameter in ...

Oct 13, 2025
CVE-2025-11651
8.8

This is a remote buffer overflow vulnerability in UTT 进取 518G routers that allows attackers to execute arbitrary code by manipulating the Profile ...

Oct 13, 2025
CVE-2025-11586
8.8

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the setNotUpgrade funct...

Oct 10, 2025
CVE-2025-11528
8.8

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the saveAutoQos functio...

Oct 9, 2025
CVE-2025-11526
8.8

This vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WifiMacFilterSet fu...

Oct 9, 2025
CVE-2025-11524
8.8

A stack-based buffer overflow vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code by manipulating the ddnsEn paramete...

Oct 9, 2025
CVE-2025-11444
8.8

A buffer overflow vulnerability in TOTOLINK N600R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP requests...

Oct 8, 2025
CVE-2025-11408
8.8

A buffer overflow vulnerability in D-Link DI-7001 MINI routers allows remote attackers to execute arbitrary code by manipulating the 'str' argument in...

Oct 7, 2025
CVE-2025-11387
8.8

A stack-based buffer overflow vulnerability exists in Tenda AC15 routers via the /goform/fast_setting_pppoe_set endpoint when manipulating the Passwor...

Oct 7, 2025
CVE-2025-11386
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC15 routers via a stack-based buffer overflow in the SetDDNSCfg functio...

Oct 7, 2025
CVE-2025-11385
8.8

A buffer overflow vulnerability in Tenda AC20 routers allows remote attackers to execute arbitrary code by manipulating the timeZone parameter. This a...

Oct 7, 2025
CVE-2025-11355
8.8

A buffer overflow vulnerability in UTT 1250GW routers allows remote attackers to execute arbitrary code by exploiting the strcpy function in the aspCh...

Oct 7, 2025
CVE-2025-11356
8.8

A buffer overflow vulnerability in Tenda AC23 routers allows remote attackers to execute arbitrary code by exploiting improper input validation in the...

Oct 7, 2025
CVE-2025-11339
8.8

A buffer overflow vulnerability in D-Link DI-7100G C1 routers allows remote attackers to execute arbitrary code by manipulating the popupId parameter ...

Oct 6, 2025
CVE-2025-11338
8.8

A buffer overflow vulnerability in D-Link DI-7100G C1 routers allows remote attackers to execute arbitrary code by manipulating the 'openid' parameter...

Oct 6, 2025
CVE-2025-11328
8.8

This vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the DDNS configuration...

Oct 6, 2025
CVE-2025-11326
8.8

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC18 routers through manipulation of the wifi_chkHz parameter in the WifiMacFi...

Oct 6, 2025
CVE-2025-11324
8.8

A stack-based buffer overflow vulnerability exists in Tenda AC18 routers via the /goform/setNotUpgrade endpoint. Attackers can remotely execute arbitr...

Oct 6, 2025
CVE-2025-11325
8.8

A stack-based buffer overflow vulnerability exists in Tenda AC18 routers via the /goform/fast_setting_pppoe_set endpoint. Attackers can remotely explo...

Oct 6, 2025
CVE-2025-11323
8.8

A buffer overflow vulnerability in the UTT 1250GW router's web interface allows remote attackers to execute arbitrary code by exploiting the strcpy fu...

Oct 6, 2025
CVE-2025-11305
8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT HiPER 840G routers through a buffer overflow in the formTaskEdit function....

Oct 5, 2025
CVE-2025-11301
8.8

A remote buffer overflow vulnerability exists in Belkin F9K1015 routers via the /goform/formWlanSetupWPS endpoint. Attackers can exploit this to poten...

Oct 5, 2025
CVE-2025-11299
8.8

A buffer overflow vulnerability in Belkin F9K1015 routers allows remote attackers to execute arbitrary code by manipulating the pppUserName parameter....

Oct 5, 2025
CVE-2025-11297
8.8

A buffer overflow vulnerability in Belkin F9K1015 routers allows remote attackers to execute arbitrary code by manipulating the webpage argument in th...

Oct 5, 2025
CVE-2025-11295
8.8

This vulnerability allows remote attackers to execute arbitrary code on Belkin F9K1015 routers via a buffer overflow in the PPPoE setup interface. Att...

Oct 5, 2025
CVE-2025-11293
8.8

A buffer overflow vulnerability in Belkin F9K1015 routers allows remote attackers to execute arbitrary code by manipulating the max_Conn parameter in ...

Oct 5, 2025
CVE-2025-11122
8.8

A stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by sending specially crafted reque...

Sep 28, 2025
CVE-2025-11120
8.8

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by exploiting the formSetServerConfig function....

Sep 28, 2025
CVE-2025-11117
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code or cause denial of ser...

Sep 28, 2025
CVE-2025-11091
8.8

A buffer overflow vulnerability exists in Tenda AC21 routers through firmware version 16.03.08.16. Attackers can remotely exploit this flaw by sending...

Sep 28, 2025
CVE-2025-10953
8.8

This is a remote buffer overflow vulnerability in UTT 1200GW and 1250GW routers affecting the formApMail endpoint. Attackers can exploit this by sendi...

Sep 25, 2025
CVE-2025-10948
8.8

A buffer overflow vulnerability in MikroTik RouterOS 7's libjson.so library allows remote attackers to execute arbitrary code or crash affected device...

Sep 25, 2025
CVE-2025-10838
8.8

A buffer overflow vulnerability in Tenda AC21 routers allows remote attackers to execute arbitrary code by manipulating the wpapsk_crypto parameter. T...

Sep 23, 2025
CVE-2025-10815
8.8

A buffer overflow vulnerability in Tenda AC20 routers allows remote attackers to execute arbitrary code or cause denial of service by sending speciall...

Sep 22, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,167 CVEs classified as CWE-119, with 124 rated critical and 854 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free