← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Openview Network Node Manager
Apr 29, 2026
May 13, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via t...Show more
Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the sel parameter.Show less
1Adobe
1Shockwave Player
Apr 29, 2026
May 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execu...Show more
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.Show less
1Artifex
1Gpl Ghostscript
Apr 29, 2026
May 12, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
1Consona
3Consona Dynamic Agent
Consona Live AssistanceConsona Subscriber Assistance
Apr 29, 2026
May 12, 2010
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vecto...Show more
Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving "CreateProcess params." NOTE: some of these details are obtained from third party information.Show less
1Tony Million
1Tuniac
Apr 29, 2026
May 11, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file.
1Ultraplayer
1Ultraplayer Media Player
Apr 29, 2026
May 11, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file.
1Transmissionbt
1Transmission
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a c...Show more
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.Show less
1Awingsoft
1Awakening Winds3d Viewer Plugin
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file.
1Deliantra
1Deliantra
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Deliantra Server before 2.82 allow remote attackers to execute arbitrary code via vectors related to (1) the command_gsay function in server/c_party.C and (2) the book implementation.
2Jan Ake Larsson
Tug
2Dvipng
Tetex
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.
1Dolphin
1Dolphin Browser
Apr 29, 2026
May 6, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
1Tonec
1Internet Download Manager
Apr 29, 2026
May 6, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server...Show more
Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.Show less
1Microsoft
1Visio
Apr 29, 2026
May 6, 2010
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-20...Show more
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.Show less
1Roxio
1Cineplayer
Apr 29, 2026
May 6, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this...Show more
Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this might overlap CVE-2007-1559.Show less
1Roxio
1Cineplayer
Apr 29, 2026
May 6, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method.
2Abcbackup
Internet Soft
2Abc Backup
Urgent Backup
Apr 29, 2026
May 5, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive.
1Mochasoft
1Mocha W32 Lpd
Apr 29, 2026
May 4, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request. NOTE: some of these deta...Show more
Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request. NOTE: some of these details are obtained from third party information.Show less
1Cursorarts
1Zipwrangler
Apr 29, 2026
May 4, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.
1Google
1Chrome
Apr 29, 2026
May 3, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
May 3, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.