← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Mar 9, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an a...Show more
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior)Show less
1Siemens
1Simcenter Star Ccm+ Viewer
Jun 17, 2026
Mar 8, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an att...Show more
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an attacker to execute code in the context of the current process.Show less
1Frrouting
1Frrouting
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
1Frrouting
1Frrouting
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.
1Frrouting
1Frrouting
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.
2Fedoraproject
Frrouting
2Fedora
Frrouting
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
1Frrouting
1Frrouting
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
1Arm
3Bifrost Gpu Kernel Driver
Midgard Gpu Kernel DriverValhall Gpu Kernel Driver
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
1Huawei
1Harmonyos
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraMacos+1 more
Jun 17, 2026
Feb 23, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
1Santesoft
1Dicom Viewer Pro
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 13.2.0.21165. User interaction is required to exploit this vulnerability in that the target must vi...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 13.2.0.21165. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15105.Show less
1Bentley
3Microstation
Microstation ConnectView
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target mus...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15392.Show less
4Debian
FedoraprojectIsync Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause...Show more
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.Show less
1Redhat
1Enterprise Linux
Jun 17, 2026
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A...Show more
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.Show less