← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Facebook
1Hhvm
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions p...Show more
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.Show less
1Opensc Project
1Opensc
Jun 17, 2026
Sep 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys wit...Show more
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.Show less
3Debian
FedoraprojectOpensc Project
3Debian Linux
FedoraOpensc
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
3Debian
FedoraprojectOpensc Project
3Debian Linux
FedoraOpensc
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
1Hanwha Security
3Srn 1673s Firmware
Srn 472s FirmwareSrn 873s Firmware
Jun 17, 2026
Sep 5, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117...Show more
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.Show less
1Ezautomation
1Ez Plc Editor
Jun 17, 2026
Sep 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of the EZ PLC Editor Versions 1.8.41 and prior.
1Ezautomation
1Ez Touch Editor
Jun 17, 2026
Sep 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of the EZ Touch Editor Versions 2.1.0 and prior.
1Robotis
1Dynamixel Sdk
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
1Fontforge
1Fontforge
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
1Lute Tab Project
1Lute Tab
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.
1Zephyrproject
1Zephyr
Nov 21, 2024
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. Th...Show more
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.Show less
1Lexmark
716500e Firmware
C734 FirmwareC736 Firmware+68 more
Jun 17, 2026
Aug 28, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
1Lexmark
716500e Firmware
C734 FirmwareC736 Firmware+68 more
Jun 17, 2026
Aug 28, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
2Debian
Xymon
2Debian Linux
Xymon
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.
2Debian
Xymon
2Debian Linux
Xymon
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
2Debian
Xymon
2Debian Linux
Xymon
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
1Ncurses Project
1Ncurses
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
1Arrayfire
1Arrayfire
Nov 21, 2024
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.
1Slice Deque Project
1Slice Deque
Nov 21, 2024
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.
1Ricoh
4Sp C250dn Firmware
Sp C250sf FirmwareSp C252dn Firmware+1 more
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firm...Show more
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.Show less