CWE-119: Buffer Overflow

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

1,172
Total CVEs
124
Critical
859
High
7.9
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
161
2025
663
2024
139
2023
70
2022
53

Top Affected Vendors

1 Tenda 185
2 Dlink 82
3 Totolink 76
4 Apple 48
5 Utt 47
6 Cadsofttools 32
7 Pcman 28
8 Freefloat 25
9 Mozilla 24
10 Fedoraproject 22

All Buffer Overflow CVEs (1,172)

CVE-2025-7084
8.8

A critical stack-based buffer overflow vulnerability in Belkin F9K1122 routers allows remote attackers to execute arbitrary code by manipulating the p...

Jul 6, 2025
CVE-2025-6953
8.8

This critical vulnerability in TOTOLINK A3002RU routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST reque...

Jul 1, 2025
CVE-2025-6939
8.8

A critical buffer overflow vulnerability in TOTOLINK A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jul 1, 2025
CVE-2025-6887
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC5 routers allows remote attackers to execute arbitrary code by sending specially craft...

Jun 30, 2025
CVE-2025-6882
8.8

A critical buffer overflow vulnerability in D-Link DIR-513 router firmware allows remote attackers to execute arbitrary code by manipulating the curTi...

Jun 30, 2025
CVE-2025-6825
8.8

A critical buffer overflow vulnerability in TOTOLINK A702R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Jun 28, 2025
CVE-2025-6751
8.8

A critical buffer overflow vulnerability in Linksys E8450 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP ...

Jun 27, 2025
CVE-2025-6734
8.8

A critical buffer overflow vulnerability in UTT HiPER 840G routers allows remote attackers to execute arbitrary code by sending specially crafted requ...

Jun 26, 2025
CVE-2025-6732
8.8

A critical buffer overflow vulnerability in UTT HiPER 840G routers allows remote attackers to execute arbitrary code by exploiting the strcpy function...

Jun 26, 2025
CVE-2025-6616
8.8

This critical vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web ...

Jun 25, 2025
CVE-2025-6614
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the ...

Jun 25, 2025
CVE-2025-6568
8.8

A critical buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 24, 2025
CVE-2025-6565
8.8

A critical stack-based buffer overflow vulnerability in Netgear WNCE3001's HTTP POST request handler allows remote attackers to execute arbitrary code...

Jun 24, 2025
CVE-2025-6511
8.8

A critical stack-based buffer overflow vulnerability in Netgear EX6150 firmware allows remote attackers to execute arbitrary code or crash the device....

Jun 23, 2025
CVE-2025-6510
8.8

A critical stack-based buffer overflow vulnerability in Netgear EX6100 firmware allows remote attackers to execute arbitrary code on affected devices....

Jun 23, 2025
CVE-2025-6486
8.8

This critical vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the form...

Jun 22, 2025
CVE-2025-6402
8.8

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...

Jun 21, 2025
CVE-2025-6400
8.8

This critical vulnerability in TOTOLINK N300RH routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST messag...

Jun 21, 2025
CVE-2025-6399
8.8

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 21, 2025
CVE-2025-6393
8.8

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP PO...

Jun 21, 2025
CVE-2025-6373
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the ...

Jun 21, 2025
CVE-2025-6371
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the ...

Jun 20, 2025
CVE-2025-6369
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating the ...

Jun 20, 2025
CVE-2025-6367
8.8

This critical vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web ...

Jun 20, 2025
CVE-2025-6337
8.8

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially...

Jun 20, 2025
CVE-2025-6334
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-867 routers allows remote attackers to execute arbitrary code by exploiting imprope...

Jun 20, 2025
CVE-2025-6328
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-815 router firmware allows remote attackers to execute arbitrary code. This affects...

Jun 20, 2025
CVE-2025-6302
8.8

A critical stack-based buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by manipulating the...

Jun 20, 2025
CVE-2025-6291
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-825 router's HTTP POST request handler allows remote attackers to execute arbitrary...

Jun 20, 2025
CVE-2025-49847
8.8

A buffer overflow vulnerability in llama.cpp's vocabulary loading code allows attackers to trigger arbitrary memory corruption via malicious GGUF mode...

Jun 17, 2025
CVE-2025-6164
8.8

A critical buffer overflow vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...

Jun 17, 2025
CVE-2025-6162
8.8

A critical buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 17, 2025
CVE-2025-6158
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-665 routers allows remote attackers to execute arbitrary code by sending specially ...

Jun 17, 2025
CVE-2025-6147
8.8

A critical buffer overflow vulnerability in TOTOLINK A702R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP...

Jun 17, 2025
CVE-2025-6149
8.8

A critical buffer overflow vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code by sending specially crafted HTT...

Jun 17, 2025
CVE-2025-6143
8.8

This critical vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST reque...

Jun 16, 2025
CVE-2025-6145
8.8

This critical vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST reque...

Jun 16, 2025
CVE-2025-6138
8.8

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 16, 2025
CVE-2025-6137
8.8

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP P...

Jun 16, 2025
CVE-2025-6129
8.8

A critical buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 16, 2025
CVE-2025-6114
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code by manipulating spec...

Jun 16, 2025
CVE-2025-6112
8.8

A critical buffer overflow vulnerability in Tenda FH1205 routers allows remote attackers to execute arbitrary code by manipulating the lanMask paramet...

Jun 16, 2025
CVE-2025-6110
8.8

A critical stack-based buffer overflow vulnerability in Tenda FH1201 routers allows remote attackers to execute arbitrary code by manipulating the 'pa...

Jun 16, 2025
CVE-2025-6091
8.8

A critical buffer overflow vulnerability in H3C GR-3000AX routers allows remote attackers to execute arbitrary code by manipulating parameters in the ...

Jun 15, 2025
CVE-2025-6090
8.8

A critical buffer overflow vulnerability in H3C GR-5400AX routers allows remote attackers to execute arbitrary code by manipulating parameters in the ...

Jun 15, 2025
CVE-2025-5978
8.8

A critical stack-based buffer overflow vulnerability in Tenda FH1202 routers allows remote attackers to execute arbitrary code by manipulating the 'pa...

Jun 10, 2025
CVE-2025-5934
8.8

A critical stack-based buffer overflow vulnerability in Netgear EX3700 devices allows remote attackers to execute arbitrary code or crash the system. ...

Jun 10, 2025
CVE-2025-5912
8.8

A critical stack-based buffer overflow vulnerability in D-Link DIR-632 router firmware allows remote attackers to execute arbitrary code via specially...

Jun 10, 2025
CVE-2025-5910
8.8

This critical vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST reque...

Jun 10, 2025
CVE-2025-5908
8.8

A critical buffer overflow vulnerability in TOTOLINK EX1200T routers allows remote attackers to execute arbitrary code by sending specially crafted HT...

Jun 10, 2025

About Buffer Overflow (CWE-119)

The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

Our database tracks 1,172 CVEs classified as CWE-119, with 124 rated critical and 859 rated high severity. The average CVSS score for Buffer Overflow vulnerabilities is 7.9.

External reference: View CWE-119 on MITRE CWE →

Monitor Buffer Overflow Vulnerabilities

Get alerted when new Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free