CWE-124
38 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Buffer Underwrite ('Buffer Underflow')
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
CVEs (38)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer...Show more |
1Fortinet 8Fortianalyzer FortimanagerFortios+5 moreJun 17, 2026 Mar 24, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and bel...Show more |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreJun 17, 2026 Mar 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreJun 17, 2026 Mar 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may...Show more |
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could lever...Show more |
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access. |
Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer underrun can be caused by a remote peer. Th...Show more |
A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious f...Show more |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function...Show more |
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buff...Show more |
A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial o...Show more |
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. |
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 Sep 1, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac...Show more |
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxJun 17, 2026 May 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. |
1Microsoft 9Windows 10 Windows 7Windows 8+6 moreApr 22, 2026 Jul 20, 2015 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind...Show more |