← Back
CWE-119

14,079 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,079)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Tivoli Netcool Application Service Monitors
Tivoli Netcool System Service Monitors
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transa...Show more
Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transaction with a long table name that is not properly handled by a packet decoder.Show less
1Ibm
2Tivoli Netcool Application Service Monitors
Tivoli Netcool System Service Monitors
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.6 HIGH· v2
Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or c...Show more
Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or cause a denial of service via a long line in (1) hrfstable.idx, (2) hrdevice.idx, (3) hrstorage.idx, or (4) lotusmapfile in the SSM Config directory, or (5) .manifest.hive in the main agent directory.Show less
1Google
1Chrome
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The PDF functionality in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via unknown vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via...Show more
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Jun 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Developer Tools API in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
1Cisco
1Nx Os
Apr 29, 2026
May 29, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and...Show more
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and purple screen of death) by sending crafted STUN packets to a VEM, aka Bug ID CSCud14825.Show less
3Debian
OpensuseWireshark
3Debian Linux
OpensuseWireshark
Apr 29, 2026
May 25, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote atta...Show more
The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.Show less
1Microsoft
8Windows 7
Windows 8Windows Rt+5 more
Apr 22, 2026
May 24, 2013
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,...Show more
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."Show less
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG data in a movie file.
1Apple
2Iphone Os
Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.263 encoding.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TeXML file.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP3 file.
1Apple
1Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FPX file.
1Apple
2Mac Os X
Quicktime
Apr 29, 2026
May 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.
1Microsys
1Promotic
Apr 29, 2026
May 23, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.