CWE-119
14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions p...Show more |
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys wit...Show more |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Sep 5, 2019 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c. |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Sep 5, 2019 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c. |
1Hanwha Security 3Srn 1673s Firmware Srn 472s FirmwareSrn 873s FirmwareJun 17, 2026 Sep 5, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117...Show more |
An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of the EZ PLC Editor Versions 1.8.41 and prior. |
An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of the EZ Touch Editor Versions 2.1.0 and prior. |
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket. |
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. |
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc. |
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. Th...Show more |
1Lexmark 716500e Firmware C734 FirmwareC736 Firmware+68 moreJun 17, 2026 Aug 28, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Various Lexmark products have a Buffer Overflow (issue 3 of 3). |
1Lexmark 716500e Firmware C734 FirmwareC736 Firmware+68 moreJun 17, 2026 Aug 28, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Various Lexmark products have a Buffer Overflow (issue 2 of 3). |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. |
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. |
An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption. |
1Slice Deque Project 1Slice Deque Nov 21, 2024 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled. |
1Ricoh 4Sp C250dn Firmware Sp C250sf FirmwareSp C252dn Firmware+1 moreJun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firm...Show more |