← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xen
1Xen
Jun 17, 2026
Jan 5, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory bef...Show more
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory. This undefined behavior was meant to be addressed by XSA-437, but the approach was not sufficient.Show less
1Xen
1Xen
Jun 17, 2026
Jan 5, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory bef...Show more
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory. Show less
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.
1Mediatek
3Nr15
Nr16Nr17
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitat...Show more
In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161837; Issue ID: MOLY01161837 (MSV-892).Show less
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...Show more
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.Show less
1Google
1Android
Jun 17, 2026
Jan 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...Show more
In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011; Issue ID: ALPS07944011.Show less
2Fedoraproject
Sqlite
2Fedora
Sqlite
Jun 17, 2026
Dec 29, 2023
N/A· v4
7.3 HIGH· v3
5.2 MEDIUM· v2
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The m...Show more
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.Show less
1Siemens
96ag1414 3em07 7ab0 Firmware
6ag1416 3es07 7ab0 Firmware6es7412 2ek07 0ab0 Firmware+6 more
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All vers...Show more
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions), SINAMICS S120 (incl. SIPLUS variants) (All versions < V5.2 SP3 HF15), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions). The affected products do not handle long file names correctly. This could allow an attacker to create a buffer overflow and create a denial of service condition for the device.Show less
1Apple
1Macos
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ex...Show more
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Dec 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system.
1Qualcomm
147Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+144 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
1Qualcomm
90Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+87 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
1Qualcomm
143Apq5053 Aa Firmware
Ar8035 FirmwareCsra6620 Firmware+140 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while running invalid audio recording from ADSP.
1Qualcomm
184315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+181 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
1Qualcomm
307315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+304 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
1Qualcomm
275315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+272 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Memory corruption while loading an ELF segment in TEE Kernel.
1Qualcomm
242315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+239 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
1Qualcomm
329315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+326 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
1Qualcomm
50Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6800 Firmware+47 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
1Ibm
2Aix
Vios
Jun 17, 2026
Dec 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 267966.