Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-124 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 6 | 5 | 0 |
▅▁▁▁▁▁▁▁▁▁▁▁▁▅██
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 2 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-4373 | 4.8 | 42.6 | — | Glib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar |
| CVE-2026-44631 | 9.8 | 41.0 | — | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow |
| CVE-2026-26199 | 5.9 | 17.4 | — | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero |
| CVE-2026-16439 | 5.8 | 15.3 | — | Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow |
| CVE-2026-71969 | 8.4 | 3.4 | — | OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations |
| CVE-2026-73075 | 4.6 | 2.0 | — | Vim: Out-of-bounds Access in Popup Opacity Handling |