← Back
CWE-119

14,049 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fetchmail
1Fetchmail
Apr 16, 2026
Dec 23, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header w...Show more
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.Show less
7Cisco
FisshIntersoft+4 more
7Ios
PuttySecurenetterm+4 more
Apr 16, 2026
Dec 23, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as dem...Show more
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.Show less
1Cisco
1Catos
Apr 16, 2026
Oct 28, 2002
N/A· v4
N/A· v3
7.1 HIGH· v2
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.
1Oneidentity
1Syslog Ng
Apr 16, 2026
Oct 28, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which...Show more
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.Show less
1Fetchmail
1Fetchmail
Apr 16, 2026
Oct 11, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (...Show more
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.Show less
1Cisco
1Ios
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.1 HIGH· v2
Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.
1Microsoft
2Data Engine
Sql Server
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to...Show more
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.Show less
1Microsoft
4Windows 2000
Windows 98Windows 98se+1 more
Apr 16, 2026
Mar 15, 2002
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been impr...Show more
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.Show less
1Microsoft
6Windows 2000
Windows 95Windows 98+3 more
Apr 16, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request....Show more
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.Show less
1Sun
2Solaris
Sunos
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
1Microsoft
1Internet Explorer
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the...Show more
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.Show less
1Fetchmail
1Fetchmail
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header.
1Open Group
1Cde Common Desktop Environment
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
2Xli
Xloadimage
2Xli
Xloadimage
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
4Mcafee
Network AssociatesPgp+1 more
5E Ppliance 300
Gauntlet FirewallIrix+2 more
Apr 16, 2026
Sep 4, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
1Sco
1Openserver
Apr 16, 2026
Aug 22, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.
1Hp
1Openview Network Node Manager
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.
1Microsoft
2Visual Basic
Visual Studio
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
1Microsoft
2Ie
Internet Explorer
Apr 16, 2026
Jan 4, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
1Sun
1Solaris
Apr 16, 2026
Dec 31, 1999
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port,...Show more
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.Show less