CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected sy...Show more |
1Outer Cgi Project 1Outer Cgi Jun 17, 2026 Apr 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitialized memory buffer from KeyValueReader. |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Mar 31, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traf...Show more |
A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process cras...Show more |
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafte...Show more |
2Gnu Netapp3Binutils Cloud BackupOntap Select Deploy Administration UtilityJun 17, 2026 Mar 26, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this...Show more |
1Esri 4Arcgis Engine Arcgis ProArcmap+1 moreJun 17, 2026 Mar 25, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to a...Show more |
A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The...Show more |
A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacke...Show more |
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds ch...Show more |
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 23, 2021 N/A· v4 5.7 MEDIUM· v3 4.6 MEDIUM· v2 The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows...Show more |
1Qualcomm 20Apq8009 Firmware Apq8053 FirmwareMdm9206 Firmware+17 moreJun 17, 2026 Mar 17, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
1Schneider Electric 3Powerlogic Ion7400 Firmware Powerlogic Ion9000 FirmwarePowerlogic Pm8000 FirmwareJun 17, 2026 Mar 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or al...Show more |
1Schneider Electric 11Ion7650 Firmware Powerlogic Ion7300 FirmwarePowerlogic Ion7550 Firmware+8 moreJun 17, 2026 Mar 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affec...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbi...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbi...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote c...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Graphics Component Elevation of Privilege Vulnerability |
The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData object...Show more |