← Back
CWE-119

14,069 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,069)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youngzsoft
1Ccproxy
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname.
1Myplugins
1Gen Msn
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these...Show more
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these details are obtained from third party information.Show less
1Bpsoft
1Hex Workshop
Apr 23, 2026
Mar 4, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some...Show more
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some of these details are obtained from third party information.Show less
1Ibm
1Aix
Apr 23, 2026
Mar 4, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
1Mpfr
1Gnu Mpfr
Apr 23, 2026
Mar 3, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in GNU MPFR 2.4.0 allow context-dependent attackers to cause a denial of service (crash) via the (1) mpfr_snprintf and (2) mpfr_vsnprintf functions.
1Capilano
1Designworks
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary code via a crafted .cct file. NOTE: some of these details are obtained from third party information.
1Adobe
4Air
Flash PlayerFlash Player For Linux+1 more
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code...Show more
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."Show less
1Orbitdownloader
1Orbit Downloader
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not prop...Show more
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.Show less
1Dmitry Baryshev
1Ksquirrel Libs
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in the mt_codec::getHdrHead function in kernel/kls_hdr/fmt_codec_hdr.cpp in ksquirrel-libs 0.8.0 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RG...Show more
Multiple stack-based buffer overflows in the mt_codec::getHdrHead function in kernel/kls_hdr/fmt_codec_hdr.cpp in ksquirrel-libs 0.8.0 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE image (aka .hdr file).Show less
1Nokia
1Nokia Pc Suite
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.
1Smcfancontrol
1Smcfancontrol
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k option.
1Tptest
1Tptest
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field. NOTE: the provenance of this information is unknow...Show more
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Feb 20, 2009
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedd...Show more
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.Show less
1Tptest
1Tptest
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information.Show less
1Raidenftpd
1Raidenftpd
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands.
1Opensuse
1Opensuse
Apr 23, 2026
Feb 18, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."
1Linux
1Linux Kernel
Apr 23, 2026
Feb 17, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via...Show more
Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe.Show less
2Barnowl
Ktools
2Barnowl
Owl
Apr 23, 2026
Feb 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a...Show more
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.Show less
1Wireshark
1Wireshark
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.
1Rimarts
1Becky! Internet Mail
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.