CWE-119
14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 7Icloud IpadosIphone Os+4 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0,...Show more |
1Apple 4Ipados Iphone OsMac Os X+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3...Show more |
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. |
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file. |
1Huawei 3Nip6800 Firmware Secospace Usg6600 FirmwareUsg9500 FirmwareJun 17, 2026 Feb 18, 2020 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference...Show more |
A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery), |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead t...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead t...Show more |
In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User executio...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a m...Show more |
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attacke...Show more |
A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsing. |
An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications th...Show more |
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used inside a bit. Applications that use libyang to parse untrusted input yang fi...Show more |
1Qualcomm 44Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+41 moreJun 17, 2026 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sn...Show more |
1Qualcomm 46Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+43 moreJun 17, 2026 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, S...Show more |
PotPlayer 1.5.40688: .avi File Memory Corruption |
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service |
HMailServer 5.3.x and prior: Memory Corruption which could cause DOS |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxNov 21, 2024 Jan 2, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process. |