← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
55Ar8035 Firmware
Qam8295p FirmwareQca6390 Firmware+52 more
Jun 17, 2026
May 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
1Nvidia
1Sbios
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.
1Nvidia
1Dgx A100 Firmware
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A successful exploit of this vulnerability may lead to denial of service, escalation o...Show more
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A successful exploit of this vulnerability may lead to denial of service, escalation of privileges, and information disclosure.Show less
1Nvidia
1Dgx A100 Firmware
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacySmmSredir SMM APIs. A successful exploit of this vulnerability may lead to deni...Show more
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacySmmSredir SMM APIs. A successful exploit of this vulnerability may lead to denial of service, escalation of privileges, and information disclosure.Show less
1Artifex
1Mujs
Jun 17, 2026
Apr 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
1Cesanta
1Mjs
Jun 17, 2026
Apr 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (DoS).
1Axiosys
1Bento4
Jun 17, 2026
Apr 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
1Arm
2Avalon Gpu Kernel Driver
Valhall Gpu Kernel Driver
Jun 17, 2026
Apr 11, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p...Show more
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.Show less
1Jtekt
1Screen Creator Advance 2
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a projec...Show more
Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information may be disclosed and/or arbitrary code may be executed.Show less
1F5
1Njs
Jun 17, 2026
Apr 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.
1Arm
2Avalon Gpu Kernel Driver
Valhall Gpu Kernel Driver
Jun 17, 2026
Apr 6, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through...Show more
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.Show less
1Bzip3 Project
1Bzip3
Jun 17, 2026
Apr 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3_decode_block.
1Irfanview
1Irfanview
Jun 17, 2026
Apr 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.
1Gnu
1Binutils
Jun 17, 2026
Apr 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
1Ibm
2Aspera Cargo
Aspera Connect
Jun 17, 2026
Apr 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID:...Show more
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.Show less
1Ibm
2Aspera Cargo
Aspera Connect
Jun 17, 2026
Apr 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID:...Show more
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.Show less
1Nvidia
1Virtual Gpu
Jun 17, 2026
Apr 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure,...Show more
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure, and data tampering.Show less
1Nvidia
1Virtual Gpu
Jun 17, 2026
Apr 1, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.
1Nvidia
1Virtual Gpu
Jun 17, 2026
Apr 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer caus...Show more
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.Show less
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
Kepserver EnterpriseKepware Kepserverex+5 more
Jun 17, 2026
Mar 29, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.Show less