CWE-124 · 40 записей
Buffer Underwrite ('Buffer Underflow')
CVE этого класса
40 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2023-25610Proof of concept | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, versfortinet · fortiweb · CWE-124 | Критическая9,8 | — | 18,3 % | 24 мар. 2025 г. |
40В плане | CVE-2018-15361Эксплойта нет | UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution.uvnc · ultravnc · CWE-124 | Критическая9,8 | — | 2,9 % | 5 мар. 2019 г. |
40В плане | CVE-2023-48230Эксплойта нет | Cap'n Proto WebSocket message can cause crashcapnproto · capnproto · CWE-124 | Критическая9,8 | — | 1,9 % | 21 нояб. 2023 г. |
39Наблюдать | CVE-2021-38578Эксплойта нет | Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.tianocore · edk2 · CWE-124 | Критическая9,8 | — | 1,0 % | 3 мар. 2022 г. |
39Наблюдать | CVE-2025-53101Эксплойта нет | ImageMagick has Stack Buffer Overflow in image.cimagemagick · imagemagick · CWE-124 | Критическая9,8 | — | 0,9 % | 14 июл. 2025 г. |
39Наблюдать | CVE-2023-32614Эксплойта нет | A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1.accusoft · imagegear · CWE-124 | Критическая9,8 | — | 0,8 % | 25 сент. 2023 г. |
39Наблюдать | CVE-2026-44631Эксплойта нет | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflowapache · http server · CWE-124 | Критическая9,8 | — | 0,7 % | 8 июн. 2026 г. |
35Наблюдать | CVE-2025-27440Эксплойта нет | Zoom Apps - Heap-based Buffer Overflowzoom · meeting software development kit · CWE-124 | Высокая8,8 | — | 0,4 % | 11 мар. 2025 г. |
35Наблюдать | CVE-2025-27439Эксплойта нет | Zoom Apps - Buffer Underflowzoom · meeting software development kit · CWE-124 | Высокая8,8 | — | 0,4 % | 11 мар. 2025 г. |
34Наблюдать | CVE-2022-20683Эксплойта нет | Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerabilitycisco · ios xe · CWE-124 | Высокая8,6 | — | 1,5 % | 15 апр. 2022 г. |
33Наблюдать | CVE-2021-38575Эксплойта нет | NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.tianocore · edk2 · CWE-124 | Высокая8,1 | — | 2,0 % | 1 дек. 2021 г. |
33Наблюдать | CVE-2026-71969Эксплойта нет | OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operationsop-tee · optee_os · CWE-124 | Высокая8,4 | — | 0,2 % | 10 авг. 2026 г. |
32Наблюдать | CVE-2021-36064Эксплойта нет | XMP Toolkit SDK SVG_Adapter ParseFullNS Buffer Underflowadobe · xmp toolkit software development kit · CWE-124 | Высокая7,8 | — | 2,7 % | 1 сент. 2021 г. |
32Наблюдать | CVE-2026-34253Эксплойта нет | A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in rCWE-124 | Высокая8,2 | — | 0,7 % | 15 мая 2026 г. |
32Наблюдать | CVE-2026-0966Эксплойта нет | Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()libssh · libssh · CWE-124 | Высокая8,2 | — | 0,6 % | 26 мар. 2026 г. |
31Наблюдать | CVE-2022-33896Эксплойта нет | A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.hancom · hancom office 2020 · CWE-124 | Высокая7,8 | — | 0,5 % | 7 окт. 2022 г. |
31Наблюдать | CVE-2024-52990Эксплойта нет | Animate | Buffer Underwrite ('Buffer Underflow') (CWE-124)adobe · animate · CWE-124 | Высокая7,8 | — | 0,4 % | 10 дек. 2024 г. |
30Наблюдать | CVE-2023-34351Эксплойта нет | Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of serviintel · performance counter monitor · CWE-124 | Высокая7,5 | — | 0,7 % | 14 февр. 2024 г. |
30Наблюдать | GHSA-5jfw-35xp-5m42Эксплойта нет | Buffer length underflow in LoginPacket causing unchecked exceptions to be thrownPackagist · pocketmine/bedrock-protocol · CWE-124 | Высокая7,5 | — | — | 5 апр. 2022 г. |
29Наблюдать | CVE-2026-5089Эксплойта нет | YAML::Syck versions before 1.38 for Perl has an out-of-bounds readtoddr · yaml::syck · CWE-124 | Высокая7,3 | — | 0,4 % | 12 мая 2026 г. |
28Наблюдать | CVE-2025-61690Эксплойта нет | KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability.keyence corporation · kv studio · CWE-124 | Высокая7,1 | — | 0,1 % | 2 окт. 2025 г. |
27Наблюдать | CVE-2018-5388Эксплойта нет | In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhastrongswan · strongswan · CWE-124 | Средняя6,5 | — | 4,0 % | 31 мая 2018 г. |
26Наблюдать | CVE-2025-61915Эксплойта нет | OpenPrinting CUPS vulnerable to stack based out-of-bound writeopenprinting · cups · CWE-124 | Средняя6,7 | — | 0,5 % | 28 нояб. 2025 г. |
26Наблюдать | CVE-2026-41499Эксплойта нет | Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()wazuh · wazuh · CWE-124 | Средняя6,5 | — | 0,4 % | 29 апр. 2026 г. |
26Наблюдать | CVE-2026-28419Эксплойта нет | Vim has Heap-based Buffer Underflow in Emacs tags parsingvim · vim · CWE-124 | Средняя6,6 | — | 0,2 % | 27 февр. 2026 г. |
- CVE-2023-2561044В плане
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, vers
КритическаяCVSS 9,8Proof of conceptEPSS 18 %fortinet · fortiweb24 мар. 2025 г.
- CVE-2018-1536140В плане
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %uvnc · ultravnc5 мар. 2019 г.
- CVE-2023-4823040В плане
Cap'n Proto WebSocket message can cause crash
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %capnproto · capnproto21 нояб. 2023 г.
- CVE-2021-3857839Наблюдать
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tianocore · edk23 мар. 2022 г.
- CVE-2025-5310139Наблюдать
ImageMagick has Stack Buffer Overflow in image.c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %imagemagick · imagemagick14 июл. 2025 г.
- CVE-2023-3261439Наблюдать
A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %accusoft · imagegear25 сент. 2023 г.
- CVE-2026-4463139Наблюдать
Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · http server8 июн. 2026 г.
- CVE-2025-2744035Наблюдать
Zoom Apps - Heap-based Buffer Overflow
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %zoom · meeting software development kit11 мар. 2025 г.
- CVE-2025-2743935Наблюдать
Zoom Apps - Buffer Underflow
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %zoom · meeting software development kit11 мар. 2025 г.
- CVE-2022-2068334Наблюдать
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cisco · ios xe15 апр. 2022 г.
- CVE-2021-3857533Наблюдать
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %tianocore · edk21 дек. 2021 г.
- CVE-2026-7196933Наблюдать
OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %op-tee · optee_os10 авг. 2026 г.
- CVE-2021-3606432Наблюдать
XMP Toolkit SDK SVG_Adapter ParseFullNS Buffer Underflow
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %adobe · xmp toolkit software development kit1 сент. 2021 г.
- CVE-2026-3425332Наблюдать
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in r
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %15 мая 2026 г.
- CVE-2026-096632Наблюдать
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %libssh · libssh26 мар. 2026 г.
- CVE-2022-3389631Наблюдать
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office 20207 окт. 2022 г.
- CVE-2024-5299031Наблюдать
Animate | Buffer Underwrite ('Buffer Underflow') (CWE-124)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · animate10 дек. 2024 г.
- CVE-2023-3435130Наблюдать
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of servi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %intel · performance counter monitor14 февр. 2024 г.
- GHSA-5jfw-35xp-5m4230Наблюдать
Buffer length underflow in LoginPacket causing unchecked exceptions to be thrown
ВысокаяCVSS 7,5Эксплойта нетPackagist · pocketmine/bedrock-protocol5 апр. 2022 г.
- CVE-2026-508929Наблюдать
YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %toddr · yaml::syck12 мая 2026 г.
- CVE-2025-6169028Наблюдать
KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %keyence corporation · kv studio2 окт. 2025 г.
- CVE-2018-538827Наблюдать
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exha
СредняяCVSS 6,5Эксплойта нетEPSS 4 %strongswan · strongswan31 мая 2018 г.
- CVE-2025-6191526Наблюдать
OpenPrinting CUPS vulnerable to stack based out-of-bound write
СредняяCVSS 6,7Эксплойта нетEPSS 0 %openprinting · cups28 нояб. 2025 г.
- CVE-2026-4149926Наблюдать
Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wazuh · wazuh29 апр. 2026 г.
- CVE-2026-2841926Наблюдать
Vim has Heap-based Buffer Underflow in Emacs tags parsing
СредняяCVSS 6,6Эксплойта нетEPSS 0 %vim · vim27 февр. 2026 г.