CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,172
Total CVEs
124
Critical
859
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,172)

CVE-2025-10792
8.8

This CVE describes a remote buffer overflow vulnerability in D-Link DIR-513 A1FW110 routers via the /goform/formWPS endpoint. Attackers can exploit th...

Sep 22, 2025
CVE-2025-10779
8.8

This CVE describes a stack-based buffer overflow vulnerability in D-Link DCS-935L IP cameras through manipulation of the HNAP_AUTH/SOAPAction argument...

Sep 22, 2025
CVE-2025-10773
8.8

A stack-based buffer overflow vulnerability in the B-Link BL-AC2100 router's web management interface allows remote attackers to execute arbitrary cod...

Sep 22, 2025
CVE-2025-10756
8.8

A buffer overflow vulnerability in UTT HiPER 840G routers allows remote attackers to execute arbitrary code by manipulating the tempName parameter in ...

Sep 20, 2025
CVE-2025-10666
8.8

A buffer overflow vulnerability in D-Link DIR-825 routers allows remote attackers to execute arbitrary code by manipulating the countdown_time paramet...

Sep 18, 2025
CVE-2025-10537
8.8

This CVE describes memory safety vulnerabilities in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers co...

Sep 16, 2025
CVE-2025-10443
8.8

A buffer overflow vulnerability in Tenda AC9 and AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted requests ...

Sep 15, 2025
CVE-2025-10385
8.8

A buffer overflow vulnerability in Mercury KM08-708H GiGA WiFi Wave2 routers allows remote attackers to execute arbitrary code by manipulating the Chg...

Sep 14, 2025
CVE-2025-10172
8.8

A buffer overflow vulnerability in UTT 750W devices up to version 3.2.2-191225 allows remote attackers to execute arbitrary code by manipulating the i...

Sep 9, 2025
CVE-2025-10171
8.8

A buffer overflow vulnerability in UTT 1250GW devices allows remote attackers to execute arbitrary code or cause denial of service. This affects all v...

Sep 9, 2025
CVE-2025-10170
8.8

A buffer overflow vulnerability in UTT 1200GW devices allows remote attackers to execute arbitrary code or cause denial of service by manipulating the...

Sep 9, 2025
CVE-2025-9938
8.8

This CVE describes a remote stack-based buffer overflow vulnerability in D-Link DI-8400 routers. Attackers can exploit this weakness to execute arbitr...

Sep 4, 2025
CVE-2025-9813
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware allows remote attackers to execute arbitrary code or crash the device by sending special...

Sep 2, 2025
CVE-2025-9791
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC20 routers via a stack-based buffer overflow in the /goform/fromAdvSet...

Sep 1, 2025
CVE-2025-9783
8.8

A buffer overflow vulnerability in TOTOLINK A702R routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter i...

Sep 1, 2025
CVE-2025-9782
8.8

This CVE describes a buffer overflow vulnerability in TOTOLINK A702R routers that allows remote attackers to execute arbitrary code by manipulating th...

Sep 1, 2025
CVE-2025-9780
8.8

This vulnerability is a remote buffer overflow in TOTOLINK A702R routers affecting the formIpQoS function. Attackers can exploit it remotely by manipu...

Sep 1, 2025
CVE-2025-9748
8.8

A stack-based buffer overflow vulnerability exists in Tenda CH22 router firmware version 1.0.0.1. Remote attackers can exploit this by sending special...

Aug 31, 2025
CVE-2025-9527
8.8

A remote stack-based buffer overflow vulnerability exists in the Linksys E1700 router's QoS configuration function. Attackers can exploit this to exec...

Aug 27, 2025
CVE-2025-9526
8.8

A remote stack-based buffer overflow vulnerability exists in the Linksys E1700 router's web interface. Attackers can exploit this by sending specially...

Aug 27, 2025
CVE-2025-9481
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating the...

Aug 26, 2025
CVE-2025-9483
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating par...

Aug 26, 2025
CVE-2025-9443
8.8

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the new_account parameter in t...

Aug 26, 2025
CVE-2025-9392
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by sending speciall...

Aug 24, 2025
CVE-2025-9363
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating the...

Aug 23, 2025
CVE-2025-9360
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the rule...

Aug 23, 2025
CVE-2025-9358
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the admp...

Aug 23, 2025
CVE-2025-9355
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating the...

Aug 22, 2025
CVE-2025-9297
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda i22 routers by exploiting a stack-based buffer overflow in the web inter...

Aug 21, 2025
CVE-2025-9299
8.8

A stack-based buffer overflow vulnerability in Tenda M3 routers allows remote attackers to execute arbitrary code by manipulating the 'Time' parameter...

Aug 21, 2025
CVE-2025-9253
8.8

A stack-based buffer overflow vulnerability in Linksys range extenders allows remote attackers to execute arbitrary code by manipulating the ssidhex p...

Aug 20, 2025
CVE-2025-9252
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the 'hin...

Aug 20, 2025
CVE-2025-9250
8.8

A stack-based buffer overflow vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary code by manipulating the...

Aug 20, 2025
CVE-2025-9248
8.8

A stack-based buffer overflow vulnerability in Linksys RE-series range extenders allows remote attackers to execute arbitrary code by manipulating the...

Aug 20, 2025
CVE-2025-9245
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the SSID...

Aug 20, 2025
CVE-2025-9089
8.8

A stack-based buffer overflow vulnerability in Tenda AC20 routers allows remote attackers to execute arbitrary code by sending specially crafted reque...

Aug 17, 2025
CVE-2025-9087
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC20 routers via a stack-based buffer overflow in the SetNetControlList ...

Aug 16, 2025
CVE-2025-9023
8.8

A buffer overflow vulnerability in Tenda AC7 and AC18 routers allows remote attackers to execute arbitrary code by manipulating the Time parameter in ...

Aug 15, 2025
CVE-2025-9006
8.8

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by exploiting the form...

Aug 15, 2025
CVE-2025-8958
8.8

A stack-based buffer overflow vulnerability exists in Tenda TX3 router firmware version 16.03.13.11_multi_TDE01. Remote attackers can exploit this by ...

Aug 14, 2025
CVE-2025-8939
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC20 routers by exploiting a buffer overflow in the WifiGuestSet functio...

Aug 14, 2025
CVE-2025-8832
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the DMZI...

Aug 11, 2025
CVE-2025-8831
8.8

A stack-based buffer overflow vulnerability in the remote management function of Linksys RE series range extenders allows remote attackers to execute ...

Aug 11, 2025
CVE-2025-8826
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating authenti...

Aug 11, 2025
CVE-2025-8824
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating RIPmode/...

Aug 11, 2025
CVE-2025-8822
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the opMo...

Aug 11, 2025
CVE-2025-8819
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the stat...

Aug 10, 2025
CVE-2025-8817
8.8

A stack-based buffer overflow vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary code by manipulating the lan2...

Aug 10, 2025
CVE-2025-31273
8.8

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malic...

Jul 30, 2025
CVE-2025-31277
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine affecting multiple Apple operating systems. Processing malicious web conten...

Jul 30, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,172 CVEs classified as CWE-119, with 124 rated critical and 859 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free