← Back
CWE-119

14,049 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youngzsoft
1Ccproxy
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.
1Cscope
1Cscope
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.
1Efs Software
1Easy Chat Server
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affecte...Show more
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.Show less
1Solarwinds
1Serv U File Server
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
8.5 HIGH· v2
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
1Oracle
2Oracle8i
Oracle9i
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
8.5 HIGH· v2
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remo...Show more
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.Show less
1Solarwinds
1Serv U File Server
Apr 16, 2026
Nov 23, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
2Debian
Oracle
2Debian Linux
Mysql
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a...Show more
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).Show less
8Clearswift
F SecureRarlab+5 more
13Cgpmcafee
F Secure Anti VirusF Secure For Firewalls+10 more
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long dir...Show more
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.Show less
5Cvs
GentooOpenbsd+2 more
5Cvs
LinuxOpenbsd+2 more
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
1Oracle
10Application Server
Collaboration SuiteDatabase Server+7 more
Apr 16, 2026
Aug 4, 2004
N/A· v4
N/A· v3
9.0 HIGH· v2
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
1Microsoft
7Windows 2000
Windows 2003 ServerWindows 98+4 more
Apr 16, 2026
Jun 1, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
3Ibm
Open GroupXi Graphics
3Aix
Cde Common Desktop EnvironmentDextop
Apr 16, 2026
May 4, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
1Openbsd
1Openbsd
Apr 16, 2026
May 4, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation tha...Show more
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.Show less
1Solarwinds
1Serv U File Server
Apr 16, 2026
Apr 20, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
1Microsoft
1Data Access Components
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
1Microsoft
1Proxy Server
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrat...Show more
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.Show less
1Fefe
1Fnord
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in httpd.c of fnord 1.6 allows remote attackers to create a denial of service (crash) and possibly execute arbitrary code via a long CGI request passed to the do_cgi function.
1Spamassassin
1Spamassassin
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.6 HIGH· v2
Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.
1Adiscon
1Winsyslog
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.8 HIGH· v2
Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.
1Emule
1Emule
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.8 HIGH· v2
eMule 0.29c allows remote attackers to cause a denial of service (crash) via a long password, possibly due to a buffer overflow.