CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite. |
1Ibm 2Security Directory Integrator Security Verify Directory IntegratorJun 17, 2026 Aug 16, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of res...Show more |
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pat...Show more |
Microsoft Edge (HTML-based) Memory Corruption Vulnerability |
1Amd 86Epyc 7203 Firmware Epyc 7203p FirmwareEpyc 72f3 Firmware+83 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.9 HIGH· v3 N/A· v2 Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity. |
1Amd 86Epyc 7203 Firmware Epyc 7203p FirmwareEpyc 72f3 Firmware+83 moreJun 17, 2026 Aug 5, 2024 N/A· v4 6.0 MEDIUM· v3 N/A· v2 Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest. |
1Qualcomm 208Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+205 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during session sign renewal request calls in HLOS. |
1Qualcomm 141Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+138 moreJun 17, 2026 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when keymaster operation imports a shared key. |
1Qualcomm 165Aqt1000 Firmware Ar8035 FirmwareFastconnect 6200 Firmware+162 moreJun 17, 2026 Aug 5, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |
1Vivotek 1Sd9364 Firmware Jun 17, 2026 Aug 3, 2024 8.7 HIGH· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argum...Show more |
1Vivotek 1Cc8160 Firmware Jun 17, 2026 Aug 3, 2024 8.7 HIGH· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Cont...Show more |
An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. |
An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. |
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: fix UBSAN warning in kv_dpm.c
Adds bounds check for sumo_vid_mapping_entry. |
1Citrix 3Netscaler Agent Netscaler ConsoleNetscaler SdxJun 17, 2026 Jul 10, 2024 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Fax Service Remote Code Execution Vulnerability |
1Qualcomm 69Csr8811 Firmware Immersive Home 214 Platform FirmwareImmersive Home 216 Platform Firmware+66 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image. |
1Qualcomm 42Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+39 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL handler in FastRPC. |
1Arm 25th Gen Gpu Architecture Firmware Valhall Gpu FirmwareJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU...Show more |
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Pat...Show more |