← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Aug 19, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.
1Ibm
2Security Directory Integrator
Security Verify Directory Integrator
Jun 17, 2026
Aug 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of res...Show more
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user. IBM X-Force ID: 228570.Show less
1Mediatek
3Nr15
Nr16Nr17
Jun 17, 2026
Aug 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pat...Show more
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529.Show less
1Microsoft
1Edge Chromium
Jun 17, 2026
Aug 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
1Amd
86Epyc 7203 Firmware
Epyc 7203p FirmwareEpyc 72f3 Firmware+83 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.9 HIGH· v3
N/A· v2
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
1Amd
86Epyc 7203 Firmware
Epyc 7203p FirmwareEpyc 72f3 Firmware+83 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
1Qualcomm
208Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+205 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption during session sign renewal request calls in HLOS.
1Qualcomm
141Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+138 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when keymaster operation imports a shared key.
1Qualcomm
165Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+162 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
1Vivotek
1Sd9364 Firmware
Jun 17, 2026
Aug 3, 2024
8.7 HIGH· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argum...Show more
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273526 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.Show less
1Vivotek
1Cc8160 Firmware
Jun 17, 2026
Aug 3, 2024
8.7 HIGH· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Cont...Show more
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273524. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.Show less
-
-
Jun 17, 2026
Jul 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.
-
-
Jun 17, 2026
Jul 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.
1Linux
1Linux Kernel
Jun 17, 2026
Jul 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix UBSAN warning in kv_dpm.c Adds bounds check for sumo_vid_mapping_entry.
1Citrix
3Netscaler Agent
Netscaler ConsoleNetscaler Sdx
Jun 17, 2026
Jul 10, 2024
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Fax Service Remote Code Execution Vulnerability
1Qualcomm
69Csr8811 Firmware
Immersive Home 214 Platform FirmwareImmersive Home 216 Platform Firmware+66 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.
1Qualcomm
42Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+39 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing IOCTL handler in FastRPC.
1Arm
25th Gen Gpu Architecture Firmware
Valhall Gpu Firmware
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU...Show more
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.Show less
1Mediatek
1Lr12a
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Pat...Show more
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297807; Issue ID: MSV-1482.Show less