CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Intel2Ethernet Controller E810 Firmware FedoraJun 17, 2026 Aug 11, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via loc...Show more |
2Linux Netapp5Element Software Hci Bootstrap OsHci Management Node+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. |
An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count...Show more |
1Powerdns 1Authoritative Server Jun 17, 2026 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception. |
1Cisco 15Ip Phone 8800 Firmware Ip Phone 8800 Series With Multiplatform FirmwareIp Phone 8811 Firmware+12 moreJun 17, 2026 Jul 22, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE...Show more |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Jul 14, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jul 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when...Show more |
3Fedoraproject Linuxptp ProjectRedhat3Enterprise Linux FedoraLinuxptpJun 17, 2026 Jul 9, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an...Show more |
4Debian FedoraprojectLinuxptp Project+1 more7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Jul 9, 2021 N/A· v4 8.8 HIGH· v3 8.0 HIGH· v2 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more |
An out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a mali...Show more |
Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the kernel driver in a user’s mode. Due to unexpected commands, the kernel driver will cause the system cr...Show more |
3Debian OpenexrRedhat3Debian Linux Enterprise LinuxOpenexrJun 17, 2026 Jul 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The...Show more |
1Jtekt 222port Efr Firmware Fl/et T V2h FirmwareNano 10gx Firmware+19 moreJun 17, 2026 Jul 1, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET...Show more |
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial...Show more |
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, inform...Show more |
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to denial of service, escalation of...Show more |
FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code. |
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor |
2Debian Djvulibre Project2Debian Linux DjvulibreJun 17, 2026 Jun 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences. |
2Debian Djvulibre Project2Debian Linux DjvulibreJun 17, 2026 Jun 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences. |