← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tivoli Storage Manager
Apr 23, 2026
Nov 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Expres...Show more
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.Show less
1Adobe
1Shockwave Player
Apr 23, 2026
Nov 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party info...Show more
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.Show less
2Ibm
Rim
2Blackberry Desktop Software
Lotus Notes Intellisync
Apr 23, 2026
Nov 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute...Show more
Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information.Show less
1Symantec
3Altiris Deployment Solution
Altiris Management PlatformAltiris Notification Server
Apr 23, 2026
Nov 3, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12,...Show more
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.Show less
1Pmail
1Pegasus Mail
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.
1Eureka Email
1Eureka Email
Apr 23, 2026
Nov 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Oct 29, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
1Squidguard
1Squidguard
Apr 23, 2026
Oct 28, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in...Show more
Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.Show less
1Squidguard
1Squidguard
Apr 23, 2026
Oct 28, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "em...Show more
Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."Show less
1Otslabs
3Otsav Dj
Otsav RadioOtsav Tv
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist i...Show more
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.Show less
1Assistanttools
1Music Tag Editor
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information...Show more
Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information.Show less
1Acoustica
1Mp3 Audio Mixer
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.
1Acoustica
1Mp3 Audio Mixer
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.
1Mixvibes
1Mixvibes
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.
1Cutepdf
1Formmax
Apr 23, 2026
Oct 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file. NOTE: the proven...Show more
Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
2Osgeo
Umn
2Mapserver
Mapserver
Apr 23, 2026
Oct 23, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-L...Show more
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.Show less
1Emc
1Documentum Applicationxtender
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via craf...Show more
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.