CWE-119
14,074 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,074)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. |
2Debian Privoxy2Debian Linux PrivoxyJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service. |
2Debian Privoxy2Debian Linux PrivoxyJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service. |
An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::...Show more |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. |
3Debian FedoraprojectLibcaca Project3Debian Linux FedoraLibcacaJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context. |
2Luxion Siemens6Keyshot Keyshot Network RenderingKeyshot Viewer+3 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL pointer dereference...Show more |
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, ca...Show more |
1Qualcomm 135Apq8009 Apq8009wApq8017+132 moreJun 17, 2026 Feb 22, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdra...Show more |
1Qualcomm 229Aqt1000 Firmware Ar8035 FirmwarePm3003a Firmware+226 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdra...Show more |
1Mitsubishielectric 41C Controller Module Setting And Monitoring Tool Cpu Module Logging Configuration ToolCw Configurator+38 moreJun 17, 2026 Feb 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior...Show more |
1Nb Connect Project 1Nb Connect Jun 17, 2026 Feb 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::...Show more |
Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local acc...Show more |
Expired pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access. |
Untrusted pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18. User interaction is required to exploit this vulnerability in that the target must visit a maliciou...Show more |
An out-of-bounds write vulnerability exists in the SGI RLE decompression functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file t...Show more |
An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerabi...Show more |