The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
Volume of CVEs assigned to CWE-124 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2426HIGH Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, W | Jul 20, 2015 | 8.8 | 97 | YES | YES |
CVE-2026-44631CRITICAL Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users | Jun 8, 2026 | 9.8 | 41 | NO | NO |
CVE-2023-25610CRITICAL A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t | Mar 24, 2025 | 9.8 | 40 | NO | NO |
CVE-2025-68114CRITICAL Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-34253HIGH A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in th | May 15, 2026 | 8.2 | 33 | NO | NO |
CVE-2025-53101CRITICAL ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command | Jul 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2018-15361CRITICAL UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network co | Mar 5, 2019 | 9.8 | 32 | NO | NO |
CVE-2021-38578CRITICAL Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. | Mar 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-26199MEDIUM HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, i | Jul 20, 2026 | 5.9 | 29 | NO | NO |
CVE-2026-5089HIGH YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.
The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#b | May 12, 2026 | 7.3 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.