← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Safenet Inc
2Softremote
Softremote1.4
Apr 23, 2026
Jun 5, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.
1Icq
1Icq
Apr 23, 2026
Jun 4, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL fil...Show more
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.Show less
1Ibm
1Db2
Apr 23, 2026
Jun 3, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a d...Show more
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.Show less
1Ibm
1Websphere Mq
Apr 23, 2026
Jun 3, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region...Show more
Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types.Show less
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted compressed PSD image.
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC compression file.
1Apple
1Itunes
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.
1Xvid
1Xvid
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attacker...Show more
Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.Show less
1Xvid
1Xvid
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by pro...Show more
Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a "missing resync marker range check" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.Show less
1Apple
1Quicktime
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file.
1Slsknet
1Soulseek
Apr 23, 2026
May 29, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query.
1Digimode10
1Maya
Apr 23, 2026
May 29, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .m3u or (2) .m3l playlist file.
1Sonicspot
1Audioactive Player
Apr 23, 2026
May 29, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 23, 2026
May 28, 2009
N/A· v4
N/A· v3
7.1 HIGH· v2
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malforme...Show more
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.Show less
1Chinagames
1Igame
Apr 23, 2026
May 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinag...Show more
Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.Show less
1Sun
1Solaris
Apr 23, 2026
May 26, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.
2Mega Nerd
Nullsoft
2Libsndfile
Winamp
Apr 23, 2026
May 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and...Show more
Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.Show less