← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have u...Show more
Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted WebP image.Show less
1Google
1Chrome
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified oth...Show more
The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.Show less
1Cisco
1Anyconnect Secure Mobility Client
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.
1Djangoproject
1Django
Apr 29, 2026
Jul 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cau...Show more
The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.Show less
1Siemens
4Simatic S7 400 Cpu 414 3 Pn/dp
Simatic S7 400 Cpu 416 3 Pn/dpSimatic S7 400 Cpu 416f 3 Pn/dp+1 more
Apr 29, 2026
Jul 31, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outage) via (1) malformed HTTP traffic or (2) malformed IP packets.
1Nlnetlabs
1Nsd
Apr 29, 2026
Jul 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
1Novell
1Zenworks Configuration Management
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attac...Show more
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter.Show less
1Citrix
1Provisioning Services
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to execute arbitrary code via a crafted string associated with date and ti...Show more
Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to execute arbitrary code via a crafted string associated with date and time data.Show less
1Twd Industries
1Remote Anything
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.
1Cpe17
1Autorun Killer
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via a crafted inf file.
1Nokia
1Pc Suite
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.
1Roy Marples
1Dhcpcd
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the get_packet method in socket.c in dhcpcd 3.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long packet.
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than...Show more
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.Show less