Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-124

MITRE ↗

CWE-124

2
CRITICAL
3
HIGH
7
MEDIUM
1
LOW
16 CVEs
9.8
CVE-2026-44631

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a

9.1
CVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

8.2
CVE-2026-0966

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-

8.2
CVE-2026-34253

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi

7.3
CVE-2026-5089

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck

6.7
CVE-2026-71969

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a

6.5
CVE-2026-41499

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo

6.5
CVE-2026-26199

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`

6.1
CVE-2026-20104

A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93

5.3
CVE-2026-28419

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'

4.4
CVE-2026-26204

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo

4.3
CVE-2026-40013

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an

2.8
CVE-2026-1485

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of

CVE-2024-36310

Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds

CVE-2024-36343

Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to

CVE-2026-73075

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupw

Frequently Asked Questions

What is CWE-124?

CWE-124 (CWE-124) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-124?

There are 17 CVE records associated with CWE-124 in our database. Of these, 2 are critical severity, 3 are high severity, and 7 are medium severity.

How can I protect against CWE-124 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-124 using AI-powered security agents.

Detect CWE-124 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-124 vulnerabilities across your infrastructure.

Get Started