CWE-119
14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Linux NetappOpensuse6Active Iq Performance Analytics Services Active Iq Unified ManagerData Availability Services+3 moreNov 21, 2024 Jul 26, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace. |
1Qualcomm 45Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+42 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible buffer overflow when number of channels passed is more than size of channel mapping array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mo...Show more |
1Qualcomm 44Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+41 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon V...Show more |
1Qualcomm 44Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+41 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Buffer overflow can occur when playing specific clip which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon M...Show more |
1Qualcomm 35Mdm9607 Firmware Mdm9640 FirmwareMsm8996au Firmware+32 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer received in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,...Show more |
1Qualcomm 28Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+25 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Buffer overflow can occur in display function due to lack of validation of header block size set by user. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdra...Show more |
1Qualcomm 51Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+48 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon...Show more |
1Qualcomm 35Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+32 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Conne...Show more |
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and T...Show more |
IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt...Show more |
The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the local system or the application to crash. IBM X-Force ID: 160200. |
1Qualcomm 24Mdm9150 Firmware Mdm9650 FirmwareMsm8996au Firmware+21 moreJun 17, 2026 Jul 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapd...Show more |
1Qualcomm 38Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+35 moreJun 17, 2026 Jul 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Possible buffer overflow at the end of iterating loop while getting the version info and lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdra...Show more |
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer. |
2Debian Moinejf2Abcm2ps Debian LinuxJun 17, 2026 Jul 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted file. The component is: front.c, function txt_add. The fixed version is:...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments. |
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fi...Show more |
1Schneider Electric 1Proclima Jun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClim...Show more |
1Schneider Electric 13Bmeh582040 Firmware Bmeh586040 FirmwareBmenoc0301 Firmware+10 moreJun 17, 2026 Jul 15, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP...Show more |
3Debian FedoraprojectJhead Project3Debian Linux FedoraJheadJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file. |