CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or p...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitra...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4,...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly ex...Show more |
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbit...Show more |
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer ov...Show more |
Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of service (application crash) or possibly...Show more |
1Siemens 10Scalance X 300 Scalance X 300 FirmwareScalance X 300eec+7 moreApr 29, 2026 Apr 18, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote...Show more |
1Abb 7Interlink Module QuickteachRobotstudio Lite+4 moreApr 29, 2026 Apr 18, 2012 N/A· v4 N/A· v3 7.7 HIGH· v2 Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to ex...Show more |