VYPR

CWE-124

Buffer Underwrite ('Buffer Underflow')

BaseIncompleteLikelihood: Medium

Description

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (40)

page 1 of 2
  • CVE-2015-2426HigKEVJul 20, 2015
    risk 0.79cvss 8.8epss 0.87

    Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute…

  • CVE-2023-25610CriMar 24, 2025
    risk 0.65cvss 9.8epss 0.18

    A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0…

  • CVE-2018-15361CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.03

    UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.

  • CVE-2026-16439CriJul 21, 2026
    risk 0.59cvss 9.1epss 0.00

    In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

  • CVE-2026-44631CriJun 8, 2026
    risk 0.57cvss 9.8epss 0.01

    Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

  • CVE-2022-20683HigApr 15, 2022
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…

  • CVE-2025-27440HigMar 11, 2025
    risk 0.55cvss 8.5epss 0.00

    Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-27439HigMar 11, 2025
    risk 0.55cvss 8.5epss 0.00

    Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2026-34253HigMay 15, 2026
    risk 0.53cvss 8.2epss 0.01

    A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow…

  • CVE-2026-0966HigMar 26, 2026
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the…

  • CVE-2021-38575HigDec 1, 2021
    risk 0.53cvss 8.1epss 0.02

    NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.

  • CVE-2025-61690HigOct 2, 2025
    risk 0.51cvss 7.8epss 0.00

    KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

  • CVE-2024-52990HigDec 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to manipulate memory in such a way…

  • CVE-2022-33896HigOct 7, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would…

  • CVE-2021-36064HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-34351HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2021-38578HigMar 3, 2022
    risk 0.48cvss 7.4epss 0.01

    Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

  • CVE-2023-32614HigSep 25, 2023
    risk 0.46cvss 7.0epss 0.01

    A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2018-5388MedMay 31, 2018
    risk 0.43cvss 6.5epss 0.04

    In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

  • CVE-2025-20695MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.