← Back
CWE-119

14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,074)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Djvulibre Project
2Debian Linux
Djvulibre
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
1Advantech
1Webaccess/hmi Designer
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAcc...Show more
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).Show less
1Sonicwall
2Sonicos
Sonicosv
Jun 17, 2026
Jun 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.
1Opentext
1Brava! Desktop
Jun 17, 2026
Jun 15, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13307.Show less
1Opentext
1Brava! Desktop
Jun 17, 2026
Jun 15, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13304.Show less
1Accusoft
1Imagegear
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can...Show more
An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Accusoft
1Imagegear
Jun 17, 2026
Jun 11, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious i...Show more
A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code e+...Show more
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code e+F15xecution due to missing length check on user supplied data, when a malicious CGF file is imported to IGSS Definition.Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
1Intel
77Nuc 10 Performance Kit Nuc10i3fnh Firmware
Nuc 10 Performance Kit Nuc10i3fnhf FirmwareNuc 10 Performance Kit Nuc10i3fnk Firmware+74 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
3Intel
NetappSiemens
14Cloud Backup
Converged Security And Manageability EngineSimatic Field Pg M5 Firmware+11 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable esc...Show more
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
1Qualcomm
26Ar7420 Firmware
Ar9580 FirmwareCsr8811 Firmware+23 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking
1Qualcomm
26Ar7420 Firmware
Ar9580 FirmwareCsr8811 Firmware+23 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking
1Qualcomm
26Ar7420 Firmware
Ar9580 FirmwareCsr8811 Firmware+23 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Memory corruption due to lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and Networking
1Qualcomm
26Ar7420 Firmware
Ar9580 FirmwareCsr8811 Firmware+23 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infrastructure and Networking
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jun 8, 2021
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Windows Hyper-V Denial of Service Vulnerability
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jun 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.