CWE-119
14,050 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,050)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Session Initiation Protocol (sip) Firmware Skinny Client Control Protocol (sccp) FirmwareApr 23, 2026 Feb 15, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message. |
1Cisco 2Session Initiation Protocol (sip) Firmware Skinny Client Control Protocol (sccp) FirmwareApr 23, 2026 Feb 15, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response. |
1Cisco 2Session Initiation Protocol (sip) Firmware Skinny Client Control Protocol (sccp) FirmwareApr 23, 2026 Feb 15, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command. |
1Cisco 2Session Initiation Protocol (sip) Firmware Skinny Client Control Protocol (sccp) FirmwareApr 23, 2026 Feb 15, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data. |
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long a...Show more |
1Ibm 2Informix Dynamic Server Informix Storage ManagerApr 23, 2026 Feb 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow a...Show more |
1Brooks Internet Software 2Rpm Remote Print Manager Elite Rpm Remote Print Manager SelectApr 23, 2026 Feb 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data...Show more |
1Larson Software Technology 1Network Print Server Apr 23, 2026 Feb 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114. |
Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC reques...Show more |
Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP4 for Windows allow remote attackers to execute arbitrary code via long arguments to multiple unspecified RPC functions,...Show more |
1Sony 2Axruploadserver Activex Control ImagestationApr 23, 2026 Feb 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a lo...Show more |
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487. |
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with...Show more |
Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response. |
Multiple heap-based buffer overflows in the (1) FTP service and (2) administration service in Titan FTP Server 6.0.5.549 allow remote attackers to cause a denial of service (daemon hang) and possibly execute arbitrary co...Show more |
Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009. |
1South River Technologies 1Titan Ftp Server Apr 23, 2026 Feb 12, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) US...Show more |
Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access." |
1Print Manager Plus 1Client Billing And Authentication Apr 23, 2026 Feb 12, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Stack-based buffer overflow in PQCore.exe in Print Manager Plus 2008 Client Billing and Authentication 7.0.127.16 allows remote attackers to cause a denial of service (service outage) via a series of long packets to TCP...Show more |
Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF. |