Skip to main content

CWE archive

CWE-124 CVEs

Programmatic archive

38 CVEs tagged with CWE-1243 Critical, 16 High, 18 Medium, 1 Low, 0 Unrated.

CVE-2026-16439

Published Jul 21, 2026

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-26199

Published Jul 20, 2026

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter,…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-44631

Published Jun 8, 2026

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. User…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-36343

Published May 19, 2026

Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited sectio…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-34253

Published May 15, 2026

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in t…

CVSS 8.2 · High
evidence mentions
6
Buzz score
37.5

CVE-2026-5089

Published May 12, 2026

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-41499

Published Apr 29, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-26204

Published Apr 29, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-20104

Published Mar 25, 2026

A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE93…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28419

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a ma…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2024-36310

Published Feb 10, 2026

Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of co…

CVSS 4.6 · Medium

CVE-2026-1485

Published Jan 27, 2026

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead…

CVSS 2.8 · Low
evidence mentions
3
Buzz score
25.4

CVE-2025-68114

Published Dec 17, 2025

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s inde…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61915

Published Nov 29, 2025

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62786

Published Oct 29, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61690

Published Oct 2, 2025

KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

CVSS 7.1 · High

CVE-2025-53101

Published Jul 14, 2025

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` comman…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-20695

Published Jul 8, 2025

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User in…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-4373

Published May 6, 2025

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the po…

CVSS 4.8 · Medium
evidence mentions
17
Buzz score
41.9

CVE-2020-9086

Published Dec 27, 2024

There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 38 CVEsPage 1 of 2