CWE-131— Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.— MITRE CWE catalog
237 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-131page 1 of 5
- CVE-2021-1647CRITICALCVSS 7.8EG 9.0⚠ KEV2021-01-12
Microsoft Defender Remote Code Execution Vulnerability
- CVE-2020-17087CRITICALCVSS 7.8EG 9.0⚠ KEV2020-11-11
Windows Kernel Local Elevation of Privilege Vulnerability
- CVE-2024-23622CRITICALCVSS 10.0EG 10.02024-01-26
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges.
- CVE-2024-23621CRITICALCVSS 10.0EG 10.02024-01-26
A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution.
- CVE-2026-52955CRITICALCVSS 9.8EG 9.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding t…
- CVE-2026-49841CRITICALCVSS 9.8EG 9.82026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request hand…
- CVE-2026-43501CRITICALCVSS 9.8EG 9.82026-05-21
In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->…
- CVE-2026-1949CRITICALCVSS 9.8EG 9.82026-04-24
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.
- CVE-2026-27820CRITICALCVSS 9.8EG 9.82026-04-16
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends c…
- CVE-2026-39892CRITICALCVSS 9.8EG 9.82026-04-08
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this co…
- CVE-2026-20911CRITICALCVSS 9.8EG 9.82026-04-07
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicio…
- CVE-2026-31806CRITICALCVSS 9.8EG 9.82026-03-13
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and…
- CVE-2026-1188CRITICALCVSS 9.8EG 9.82026-01-29
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer s…
- CVE-2025-66216CRITICALCVSS 9.8EG 9.82025-11-29
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arb…
- CVE-2025-1861CRITICALCVSS 9.8EG 9.82025-03-30
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limi…
- CVE-2024-23606CRITICALCVSS 9.8EG 9.82024-02-20
An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can pro…
- CVE-2023-5941CRITICALCVSS 9.8EG 9.82023-11-08
In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams whe…
- CVE-2023-4257CRITICALCVSS 9.8EG 9.82023-10-13
Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
- CVE-2023-24819CRITICALCVSS 9.8EG 9.82023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of…
- CVE-2022-33211CRITICALCVSS 9.8EG 9.82023-04-13
memory corruption in modem due to improper check while calculating size of serialized CoAP message
- CVE-2021-21824CRITICALCVSS 9.8EG 9.82021-06-11
An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vuln…
- CVE-2021-0254CRITICALCVSS 9.8EG 9.82021-04-22
A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) conditio…
- CVE-2021-27378CRITICALCVSS 9.8EG 9.82021-02-18
An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.
- CVE-2020-15350CRITICALCVSS 9.8EG 9.82020-07-07
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_est…
- CVE-2019-10500CRITICALCVSS 9.8EG 9.82019-12-18
While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobil…
- CVE-2019-10627CRITICALCVSS 9.8EG 9.82019-11-21
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prio…
- CVE-2004-1363CRITICALCVSS 9.8EG 9.82004-08-04
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
- CVE-2004-0434CRITICALCVSS 9.8EG 9.82004-07-07
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.
- CVE-2003-0899CRITICALCVSS 9.8EG 9.82003-11-03
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and …
- CVE-2002-1347CRITICALCVSS 9.8EG 9.82002-12-18
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be…
- CVE-2001-0248CRITICALCVSS 9.8EG 9.82001-06-18
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
- CVE-2001-0249CRITICALCVSS 9.8EG 9.82001-06-18
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
- CVE-2023-45871CRITICALCVSS 7.5EG 9.82023-10-15
An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.
- CVE-2023-0568CRITICALCVSS 7.5EG 9.82023-02-16
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after…
- CVE-2018-14618CRITICALCVSS 7.5EG 9.82018-09-05
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area…
- CVE-2021-38435CRITICALCVSS 6.6EG 9.82022-05-05
RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may result in a buffer overflow.
- CVE-2021-38423CRITICALCVSS 6.6EG 9.82022-05-05
All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow.
- CVE-2026-41197CRITICALCVSS 9.3EG 9.32026-04-23
Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can invoke external functions through foreign…
- CVE-2026-22590CRITICALCVSS 9.1EG 9.12026-09-09
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while …
- CVE-2024-45287CRITICALCVSS 7.5EG 9.12024-09-05
A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.
- CVE-2023-50736CRITICALCVSS 9.0EG 9.02024-02-28
A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2020-11901CRITICALCVSS 9.0EG 9.02020-06-17
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
- CVE-2026-95509HIGHCVSS 8.8EG 8.82026-09-29
Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.
- CVE-2026-69598HIGHCVSS 8.8EG 8.82026-09-08
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
- CVE-2026-55827HIGHCVSS 8.8EG 8.82026-07-10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allo…
- CVE-2026-44420HIGHCVSS 8.8EG 8.82026-05-29
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too…
- CVE-2025-62550HIGHCVSS 8.8EG 8.82025-12-09
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
- CVE-2025-27074HIGHCVSS 8.8EG 8.82025-11-04
Memory corruption while processing a GP command response.
- CVE-2025-55297HIGHCVSS 8.8EG 8.82025-08-21
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability …
- CVE-2021-21793HIGHCVSS 8.8EG 8.82021-07-08
An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear 19.8 and 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious f…
Map vulnerabilities like CWE-131 to your infrastructure
EchelonGraph correlates every CVE — across CWE-131 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →