← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB moun...Show more
Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.Show less
1Coolplayer
1Coolplayer
Apr 23, 2026
Apr 27, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE:...Show more
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.Show less
4Apple
FoolabsGlyphandcog+1 more
4Cups
PopplerXpdf+1 more
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
4Apple
FoolabsGlyphandcog+1 more
4Cups
PopplerXpdf+1 more
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of...Show more
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.Show less
3Apple
FoolabsGlyphandcog
3Cups
XpdfXpdfreader
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
3Apple
FoolabsGlyphandcog
3Cups
XpdfXpdfreader
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JB...Show more
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.Show less
1Clamav
1Clamav
Apr 23, 2026
Apr 23, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via...Show more
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.Show less
1Xilisoft
1Xilisoft Video Converter
Apr 23, 2026
Apr 22, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in...Show more
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .cue file.Show less
1Elecard
1Elecard Avc Hd Player
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 filename in a playlist (.xpl) file.
1Ibm
1Aix
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.
1Sebastian Fernandez
1Zervit
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c.
1Dawningsoft
1Powerchm
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an HTML file with a link to a long URL, as demonstr...Show more
Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an HTML file with a link to a long URL, as demonstrated by a .rar URL.Show less
1Heikki Ylinen
1Apollo
Apr 23, 2026
Apr 21, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Easy Rm To Mp3 Converter
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.
1Mini Stream
1Shadow Stream Recorder
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Rm Mp3 Converter
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Wm Downloader
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Rm Downloader
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Ripper
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
1Mini Stream
1Asx To Mp3 Converter
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.