The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Volume of CVEs assigned to CWE-131 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
208 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42945HIGH NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or s | May 13, 2026 | 8.1 | 79 | NO | NO |
CVE-2023-36824HIGH Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap o | Jul 11, 2023 | 8.8 | 69 | NO | NO |
CVE-2020-17087HIGH Windows Kernel Local Elevation of Privilege Vulnerability | Nov 11, 2020 | 7.8 | 64 | YES | NO |
CVE-2020-8450HIGH An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. | Feb 4, 2020 | 7.3 | 64 | NO | NO |
CVE-2020-6113HIGH An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When process | Sep 17, 2020 | 7.8 | 56 | NO | NO |
CVE-2005-3120CRITICAL Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian chara | Oct 17, 2005 | 9.8 | 53 | NO | YES |
CVE-2003-0899CRITICAL Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger t | Nov 3, 2003 | 9.8 | 53 | NO | YES |
CVE-2005-2103CRITICAL Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an a | Aug 16, 2005 | 9.8 | 49 | NO | YES |
CVE-2026-42055HIGH NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 o | Jun 17, 2026 | 8.1 | 43 | NO | NO |
CVE-2020-11901CRITICAL The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. | Jun 17, 2020 | 9.0 | 41 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.