← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asrmicro
2Asr1803 Firmware
Asr1806 Firmware
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory Corruption in SIM management while USIMPhase2init
1Asrmicro
2Asr1803 Firmware
Asr1806 Firmware
Jun 17, 2026
Nov 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in IMS while calling VoLTE Streamingmedia Interface
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Nov 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the...Show more
A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. Show less
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Nov 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to...Show more
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. Show less
1Siemens
2Jt2go
Teamcenter Visualization
Jun 17, 2026
Nov 21, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context...Show more
The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process.Show less
1Fujielectric
2Tellus
Tellus Lite
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9...Show more
Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed. Show less
1Intel
3Qat Driver Firmware
Quickassist Technology Driver FirmwareQuickassist Technology Library
Jun 17, 2026
Nov 14, 2023
N/A· v4
2.3 LOW· v3
N/A· v2
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.
1Intel
36Compute Module Hns2600bp Firmware
Compute Module Hns2600bpb24 FirmwareCompute Module Hns2600bpb24r Firmware+33 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access.
2Amd
Intel
6Radeon Pro Vega 56 Firmware
Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows DWM Core Library Elevation of Privilege Vulnerability
2Silabs
Weston Embedded
3Cesium Net
Gecko Software Development KitUc Http
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a mal...Show more
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
2Silabs
Weston Embedded
3Cesium Net
Gecko Software Development KitUc Http
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious...Show more
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
2Silabs
Weston Embedded
3Cesium Net
Gecko Software Development KitUc Http
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious...Show more
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
2Silabs
Weston Embedded
3Cesium Net
Gecko Software Development KitUc Http
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request t...Show more
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.Show less
2Gnu
Xen
2Grub
Xen
Jun 17, 2026
Nov 10, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementatio...Show more
An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation. Show less
1Arm
1Valhall Gpu Kernel Driver
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.
1Qualcomm
198315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+195 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in TZ Secure OS while loading an app ELF.
2Opensc Project
Redhat
2Enterprise Linux
Opensc
Jun 17, 2026
Nov 6, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an at...Show more
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.Show less
2Php
Redhat
3Enterprise Linux
PhpSoftware Collections
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
1Citrix
2Netscaler Application Delivery Controller
Netscaler Gateway
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server