← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
168Xeon Bronze 3204 Firmware
Xeon Bronze 3206r FirmwareXeon E 2124 Firmware+165 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
1Intel
37Xeon E3 1220 V5 Firmware
Xeon E3 1220 V6 FirmwareXeon E3 1225 V5 Firmware+34 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
1Amd
83Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+80 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
2Qemu
Redhat
2Enterprise Linux
Qemu
Jun 17, 2026
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The high...Show more
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.Show less
1Amd
30Ryzen 3 5300g Firmware
Ryzen 3 5300ge FirmwareRyzen 5 2600 Firmware+27 more
Jun 17, 2026
May 10, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.
1Nvidia
1Jetson Linux
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.6 MEDIUM· v3
4.4 MEDIUM· v2
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to co...Show more
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.Show less
2Debian
Gpac
2Debian Linux
Gpac
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it alloc...Show more
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.Show less
1Dell
20C4130 Firmware
C6320 FirmwareFc430 Firmware+17 more
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this v...Show more
Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.Show less
3Apple
FedoraprojectVim
3Fedora
MacosVim
Jun 17, 2026
Apr 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
2Fedoraproject
Opensc Project
2Fedora
Opensc
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
3Fedoraproject
Opensc ProjectRedhat
3Enterprise Linux
FedoraOpensc
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
1Pixar
1Openusd
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the...Show more
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability could be used to bypass mitigations and aid additional exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided file.Show less
1Fisglobal
1Gt.m
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segme...Show more
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.Show less
1Fisglobal
1Gt.m
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a...Show more
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.Show less
1Fisglobal
1Gt.m
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use t...Show more
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of the flow of execution.Show less
1Gerbv Project
1Gerbv
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Ger...Show more
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Accusoft
1Imagegear
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file t...Show more
An out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Artifex
1Ghostpcl
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruptio...Show more
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.Show less