CWE-124: Buffer Underflow
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
39 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-27440 — Zoom Apps - Heap-based Buffer Overflow
- CVE-2025-27439 — Zoom Apps - Buffer Underflow
- CVE-2026-44631 — Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2025-61690 — KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted fil
- CVE-2024-52990 — Animate | Buffer Underwrite ('Buffer Underflow') (CWE-124)
- CVE-2025-53101 — ImageMagick has Stack Buffer Overflow in image.c
- CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
- CVE-2025-62786 — Wazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissions
- CVE-2026-20104 — A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93
- CVE-2026-5089 — YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
- CVE-2025-61915 — OpenPrinting CUPS vulnerable to stack based out-of-bound write
- CVE-2026-0966 — Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
- CVE-2026-41499 — Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()
- CVE-2026-28419 — Vim has Heap-based Buffer Underflow in Emacs tags parsing
- CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
- CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
- CVE-2025-68114 — Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
- CVE-2024-36310 — Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds
- CVE-2026-73075 — Vim: Out-of-bounds Access in Popup Opacity Handling
- CVE-2024-36343 — Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to
Recently published
- CVE-2026-40013 — An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an
- CVE-2026-73075 — Vim: Out-of-bounds Access in Popup Opacity Handling
- CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
- CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
- CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
- CVE-2026-44631 — Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2024-36343 — Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to
- CVE-2026-5089 — YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
- CVE-2026-41499 — Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()
- CVE-2026-26204 — Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData
- CVE-2026-0966 — Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
- CVE-2026-20104 — A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93
- CVE-2026-28419 — Vim has Heap-based Buffer Underflow in Emacs tags parsing
- CVE-2024-36310 — Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds
- CVE-2025-68114 — Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
- CVE-2025-61915 — OpenPrinting CUPS vulnerable to stack based out-of-bound write
- CVE-2025-62786 — Wazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissions
- CVE-2025-61690 — KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted fil
- CVE-2025-53101 — ImageMagick has Stack Buffer Overflow in image.c
- CVE-2025-20695 — In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv