← Back
CWE-119

14,050 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,050)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dvrstation
1Dvrstation Cms
Apr 23, 2026
Oct 14, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.
1Sun
1Java System Web Proxy Server
Apr 23, 2026
Oct 13, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.
1Hp
1Openview Network Node Manager
Apr 23, 2026
Oct 13, 2008
N/A· v4
N/A· v3
9.0 HIGH· v2
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE...Show more
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Oct 10, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box c...Show more
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Oct 10, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Oct 10, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
1Vim
1Vim
Apr 23, 2026
Oct 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw...Show more
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.Show less
1Tonec Inc.
1Internet Download Manager
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via...Show more
Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. NOTE: this is probably a different vulnerability than CVE-2005-2210.Show less
1Herosoft
1Hero Dvd Player
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Mplayer.exe in Herosoft Inc. Hero DVD Player 3.0.8 allows user-assisted remote attackers to execute arbitrary code via an M3u file with a "long entry." NOTE: the provenance of this informati...Show more
Heap-based buffer overflow in Mplayer.exe in Herosoft Inc. Hero DVD Player 3.0.8 allows user-assisted remote attackers to execute arbitrary code via an M3u file with a "long entry." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Condor Project
1Condor
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Stack-based buffer overflow in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
3Iseemedia
Mgi SoftwareRoxio
3Lpviewer
LpviewerLpviewer
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) e...Show more
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.Show less
1Numark
1Cue
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname...Show more
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname.Show less
1Cambridge Computer Corporation
1Vxftpsrv
Apr 23, 2026
Oct 6, 2008
N/A· v4
N/A· v3
9.0 HIGH· v2
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request.
1Mirc
1Mirc
Apr 23, 2026
Oct 6, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.
2Bittorrent
Utorrent
2Bittorrent
Utorrent
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi...Show more
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.Show less
1Alcatel
1Aos
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01,...Show more
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote attackers to execute arbitrary code via a long Session cookie.Show less
1Trend Micro
1Officescan
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to execute arbitrary code via unspecified vectors.
1Safer Networking
1Filealyzer
Apr 23, 2026
Oct 2, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via an executable with malformed version d...Show more
Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via an executable with malformed version data.Show less
2Jasper Project
Redhat
2Enterprise Virtualization
Jasper
Apr 23, 2026
Oct 2, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use...Show more
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.Show less
1Realflex Technologies Ltd
1Realwin Server
Apr 23, 2026
Sep 29, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.