CWE-119
14,219 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,219)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the...Show more |
A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header. |
1Open Group 1Cde Common Desktop Environment Apr 16, 2026 Dec 6, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. |
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field. |
4Mcafee Network AssociatesPgp+1 more5E Ppliance 300 Gauntlet FirewallIrix+2 moreApr 16, 2026 Sep 4, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. |
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter. |
HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter. |
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands. |
Buffer overflow in Internet Explorer 4.0 via EMBED tag. |
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port,...Show more |
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. |
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. |
1Microsoft 3Internet Information Server Windows 2000Windows NtApr 16, 2026 Jun 16, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. |
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. |
Buffer overflow in NetMeeting allows denial of service and remote command execution. |
3Bsdi CalderaRedhat3Bsd Os LinuxOpenlinuxApr 16, 2026 Oct 12, 1998 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. |
Solaris ufsrestore buffer overflow. |
root privileges via buffer overflow in eject command on SGI IRIX systems. |