CWE-124: CWE-124

12
Total CVEs
1
Critical
8
High
7.3
Avg CVSS

Yearly Trend

2026
1
2025
6
2024
2
2022
2
2021
1

Top Affected Vendors

1 Adobe 2
2 Fortinet 1
3 Mediatek 1
4 Openwrt 1
5 Google 1
6 Intel 1
7 Cisco 1
8 Imagemagick 1
9 Debian 1
10 Openprinting 1

All CWE-124 CVEs (12)

CVE-2023-25610
EPSS 25% 9.8

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices via crafted req...

Mar 24, 2025
CVE-2022-20683
8.6

This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending crafted packets from the wired network to a...

Apr 15, 2022
CVE-2025-62786
8.1

A heap-based out-of-bounds write vulnerability in Wazuh's decode_win_permissions function allows writing a NULL byte before an allocated buffer. Compr...

Oct 29, 2025
CVE-2025-61690
7.8

KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability that allows arbitrary code execution when processing specially crafted fil...

Oct 2, 2025
CVE-2024-52990
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain a buffer underflow vulnerability that could allow arbitrary code execution when a user opens...

Dec 10, 2024
CVE-2021-36064
7.8

CVE-2021-36064 is a buffer underflow vulnerability in Adobe XMP Toolkit that could allow arbitrary code execution when a user opens a malicious file. ...

Sep 1, 2021
CVE-2023-34351
7.5

A buffer underflow vulnerability in Intel PCM software versions before 202307 allows unauthenticated attackers to potentially cause denial of service ...

Feb 14, 2024
CVE-2025-53101
7.4

A stack overflow vulnerability in ImageMagick's mogrify command allows attackers to crash the application or potentially execute arbitrary code by pro...

Jul 14, 2025
CVE-2021-38578
7.4

CVE-2021-38578 is a buffer underflow vulnerability in Tianocore EDK II's System Management Mode (SMM) entry point that allows attackers to corrupt SMR...

Mar 3, 2022
CVE-2025-20694
6.5

This vulnerability in MediaTek Bluetooth firmware allows remote attackers to cause a system crash via an uncaught exception, leading to denial of serv...

Jul 8, 2025
CVE-2025-61915
6.0

This vulnerability allows users in the lpadmin group to exploit an out-of-bounds write vulnerability in CUPS by modifying configuration files through ...

Nov 29, 2025
CVE-2026-1485
2.8

A buffer underflow vulnerability in Glib's content type parsing logic allows integer wraparound for very large inputs, leading to pointer underflow an...

Jan 27, 2026

About CWE-124 (CWE-124)

Our database tracks 12 CVEs classified as CWE-124, with 1 rated critical and 8 rated high severity. The average CVSS score for CWE-124 vulnerabilities is 7.3.

External reference: View CWE-124 on MITRE CWE →

Monitor CWE-124 Vulnerabilities

Get alerted when new CWE-124 CVEs affect your infrastructure.

Start Monitoring Free