CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and w...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and F...Show more |
A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg_info le...Show more |
1Multimon Ng Project 1Multimon Ng Jun 17, 2026 Dec 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in multimon-ng. It has been rated as critical. This issue affects the function add_ch of the file demod_flex.c. The manipulation of the argument ch leads to format string. Upgrading to version 1...Show more |
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improp...Show more |
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A |
Product: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/A |
Product: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/A |
In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed...Show more |
Product: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/A |
Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A |
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination. |
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox. |
Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a rea...Show more |
A vulnerability classified as problematic was found in pacparser up to 1.3.x. Affected by this vulnerability is the function pacparser_find_proxy of the file src/pacparser.c. The manipulation of the argument url leads to...Show more |
1Qualcomm 204Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+201 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial...Show more |
1Qualcomm 98Aqt1000 Firmware Ar8035 FirmwareQam8295p Firmware+95 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caches in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon...Show more |
1Linux Loader Project 1Linux Loader Jun 17, 2026 Dec 13, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In versions prior to 0.8.1, the linux-loader crate uses the offsets and sizes provided in the ELF headers to determine the offsets to read from. If those offsets point beyond the end of the file this could lead to Virtua...Show more |
1Hp 2700Color Laserjet Cm4540 Mfp Cc419a Firmware Color Laserjet Cm4540 Mfp Cc420a FirmwareColor Laserjet Cm4540 Mfp Cc421a Firmware+2697 moreJun 17, 2026 Dec 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. |
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applic...Show more |