← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Condor Project
1Condor
Apr 29, 2026
Sep 28, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors.
2Google
Microsoft
9Chrome
Windows 7Windows 8+6 more
Apr 29, 2026
Sep 26, 2012
N/A· v4
7.8 HIGH· v3
10.0 HIGH· v2
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as...Show more
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."Show less
1Google
1Chrome
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vu...Show more
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Sep 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vu...Show more
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883.Show less
1Ibm
1Informix Dynamic Server
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION st...Show more
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message.
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and...Show more
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vector...Show more
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.Show less
1Caminova
1Djvu Browser Plug In
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file.
1Ricoh
2Dl 10
Sr10 Ftp Server
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP comman...Show more
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.Show less
1Flashfxp
1Flashfxp
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.
1Novell
1Groupwise
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a craf...Show more
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.Show less