← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
Apr 29, 2026
Feb 28, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and s...Show more
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.Show less
1Cisco
1Unified Presence Server
Apr 29, 2026
Feb 27, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Unified Presence Server (CUPS) 8.6, 9.0, and 9.1 before 9.1.1 allows remote attackers to cause a denial of service (CPU consumption) via crafted packets to the SIP TCP port, aka Bug ID CSCua89930.
1Adobe
1Flash Player
Apr 29, 2026
Feb 27, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the broker service in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows attackers to execu...Show more
Buffer overflow in the broker service in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows attackers to execute arbitrary code via unspecified vectors.Show less
1Cisco
2Adaptive Security Appliance
Adaptive Security Appliance Software
Apr 29, 2026
Feb 25, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (connections-table memory consumption) via crafted packets, aka Bug ID CSCue46386.
1Fedoraproject
1Sssd
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Servic...Show more
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.Show less
1Infradead
1Openconnect
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.
1Nuance
2Pdf Reader
Pdf Reader Plus
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.
1Bigantsoft
1Bigant Im Message Server
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in...Show more
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.Show less
13s Software
1Codesys Gateway Server
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of servic...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.Show less
1Vmware
2Vcenter Server
Vcenter Server Appliance
Apr 29, 2026
Feb 22, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Feb 22, 2013
N/A· v4
N/A· v3
6.6 MEDIUM· v2
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impa...Show more
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Feb 22, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system cra...Show more
arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.Show less
1Ibm
1Websphere Message Broker
Apr 29, 2026
Feb 20, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (inf...Show more
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.Show less
4Canonical
MozillaOpensuse+1 more
9Enterprise Linux Aus
Enterprise Linux DesktopEnterprise Linux Eus+6 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of...Show more
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.Show less
1Symantec
2Encryption Desktop
Pgp Desktop
Apr 29, 2026
Feb 18, 2013
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application.
1Pidgin
1Pidgin
Apr 29, 2026
Feb 16, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.
1Schneider Electric
1Accutech Manager
Apr 29, 2026
Feb 15, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.
1Wellintech
1Kingview
Apr 29, 2026
Feb 15, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrar...Show more
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet.Show less
1Adobe
1Shockwave Player
Apr 29, 2026
Feb 13, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.