← Back
CWE-119

14,049 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pcre
1Pcre
Apr 23, 2026
Nov 7, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequ...Show more
Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.Show less
1Sonicwall
1Ssl Vpn
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote attackers to execute arbitrary code via a long (1) serverAddress, (2) s...Show more
Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote attackers to execute arbitrary code via a long (1) serverAddress, (2) sessionId, (3) clientIPLower, (4) clientIPHigher, (5) userName, (6) domainName, or (7) dnsSuffix Unicode property value. NOTE: the AddRouteEntry vector is covered by CVE-2007-5603.Show less
1Sonicwall
1Ssl Vpn
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second...Show more
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.Show less
1Ssreader
1Ultra Star Reader
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild. NOTE: the provenance of this...Show more
Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Ibm
1Aix
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.
1Ibm
1Aix
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.
1Ibm
1Aix
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
1Ibm
1Aix
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
1Novell
1Bordermanager
Apr 23, 2026
Nov 2, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree...Show more
Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with a wide-character backslash or NULL character.Show less
1Mono
1Mono
Apr 23, 2026
Nov 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
1Grandstream
1Ht488
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP INVITE message.
1Gom Player
1Gom Player
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to t...Show more
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.Show less
1Realnetworks
3Realone Player
RealplayerRealplayer Enterprise
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file.
1Realnetworks
2Realone Player
Realplayer
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file.
1Ipswitch
2Imail Client
Imail Server
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message.
1Realnetworks
3Realone Player
RealplayerRealplayer Enterprise
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with...Show more
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.Show less
1Realnetworks
3Realone Player
RealplayerRealplayer Enterprise
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed reco...Show more
Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.Show less
3Debian
OpensuseQemu
3Debian Linux
OpensuseQemu
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp...Show more
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.Show less
1Trend Micro
2Pc Cillin Internet Security 2007
Scan Engine
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.6 MEDIUM· v2
The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter de...Show more
The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality. NOTE: this can be leveraged for privilege escalation by exploiting a buffer overflow in the handler for IOCTL 0xa0284403.Show less
1Nufw
1Nufw
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in the samp_send function in nuauth/sasl.c in NuFW before 2.2.7 allows remote attackers to cause a denial of service via unspecified input on which base64 encoding is performed. NOTE: some of t...Show more
Heap-based buffer overflow in the samp_send function in nuauth/sasl.c in NuFW before 2.2.7 allows remote attackers to cause a denial of service via unspecified input on which base64 encoding is performed. NOTE: some of these details are obtained from third party information.Show less