CWE-124— Buffer Underwrite
34 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-124page 1 of 1
- CVE-2015-2426HIGHCVSS 8.8EG 9.0⚠ KEV2015-07-20
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1…
- CVE-2018-15361CRITICALCVSS 9.8EG 9.82019-03-05
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1…
- CVE-2018-5388MEDIUMCVSS 6.5EG 6.52018-05-31
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
- CVE-2020-9086MEDIUMCVSS 4.3EG 4.32024-12-27
There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service…
- CVE-2021-36064HIGHCVSS 7.8EG 7.82021-09-01
XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vict…
- CVE-2021-38575HIGHCVSS 8.1EG 8.12021-12-01
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
- CVE-2021-38578HIGHCVSS 7.4EG 9.82022-03-03
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
- CVE-2022-20683HIGHCVSS 8.6EG 8.62022-04-15
A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…
- CVE-2022-33896HIGHCVSS 7.8EG 7.82022-10-07
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can…
- CVE-2023-25610CRITICALCVSS 9.8EG 9.82025-03-24
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy vers…
- CVE-2023-31130MEDIUMCVSS 4.1EG 4.12023-05-25
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for conf…
- CVE-2023-32614HIGHCVSS 7.0EG 7.02023-09-25
A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this…
- CVE-2023-34351HIGHCVSS 7.5EG 7.52024-02-14
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2023-48230MEDIUMCVSS 5.9EG 5.92023-11-21
Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer underrun can be caused by a remote peer. The underrun always w…
- CVE-2024-33763HIGHCVSS 7.5EG 7.52024-05-01
lunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp.
- CVE-2024-36310MEDIUMCVSS 4.6EG 0.02026-02-10
Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.
- CVE-2024-36343MEDIUMCVSS 4.6EG 4.62026-05-19
Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potenti…
- CVE-2024-52990HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerabil…
- CVE-2025-20694MEDIUMCVSS 6.5EG 7.52025-07-08
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0975…
- CVE-2025-20695MEDIUMCVSS 6.5EG 7.52025-07-08
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0974…
- CVE-2025-27439HIGHCVSS 8.5EG 8.52025-03-11
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
- CVE-2025-27440HIGHCVSS 8.5EG 8.52025-03-11
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
- CVE-2025-4373MEDIUMCVSS 4.8EG 4.82025-05-06
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.
- CVE-2025-53101HIGHCVSS 7.4EG 7.42025-07-14
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in…
- CVE-2025-61690HIGHCVSS 7.8EG 7.82025-10-02
KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
- CVE-2025-61915MEDIUMCVSS 6.0EG 6.02025-11-29
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cu…
- CVE-2025-62786HIGHCVSS 8.1EG 8.12025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer alloca…
- CVE-2025-68114MEDIUMCVSS 4.8EG 4.82025-12-17
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer unde…
- CVE-2026-0966HIGHCVSS 8.2EG 6.52026-03-26
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program…
- CVE-2026-1485LOWCVSS 2.8EG 2.82026-01-27
A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results i…
- CVE-2026-26204MEDIUMCVSS 4.4EG 4.42026-04-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 …
- CVE-2026-34253HIGHCVSS 8.2EG 8.22026-05-15
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed in…
- CVE-2026-41499MEDIUMCVSS 6.5EG 6.52026-04-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exist in parse_uname_string() (remoted_op.c)…
- CVE-2026-5089HIGHCVSS 7.3EG 7.32026-05-12
YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a c…
Map vulnerabilities like CWE-124 to your infrastructure
EchelonGraph correlates every CVE — across CWE-124 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →