CWE-119
14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibmspack+1 moreJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim mus...Show more |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass...Show more |
1Cisco 57Esw2 350g52dc Firmware Esw2 550x48dc FirmwareSf200 24 Firmware+54 moreJun 17, 2026 Jul 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on a...Show more |
The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management interface that is pr...Show more |
3Debian DosboxFedoraproject3Debian Linux DosboxFedoraJun 17, 2026 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. |
1Moxa 4Oncell G3470a Lte Eu T Firmware Oncell G3470a Lte Eu FirmwareOncell G3470a Lte Us T Firmware+1 moreNov 21, 2024 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424. |
1Moxa 2Oncell G3150 Hspa T Firmware Oncell G3150 Hspa FirmwareNov 21, 2024 Jul 3, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420. |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles...Show more |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /var/www/video folder. It seems that this binary dumps the HTTP VERB in the system logs. As a part of...Show more |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary orthrus in /sbin folder of the device handles all the UPnP connections received by the device. It seems that the binary performs a sprintf opera...Show more |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operatio...Show more |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as...Show more |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as...Show more |
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code. |
1Lexmark 326500 Firmware Cx310 FirmwareCx410 Firmware+29 moreNov 21, 2024 Jun 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Various Lexmark devices have a Buffer Overflow (issue 1 of 2). |
1Lexmark 34Cx421 Firmware Cx522 FirmwareCx62x Firmware+31 moreNov 21, 2024 Jun 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Various Lexmark devices have a Buffer Overflow (issue 2 of 2). |
Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in libutil.a. Remote attackers could leverage this vulnerability to cause a denial of service via a craf...Show more |
A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long resp...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 24, 2019 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command s...Show more |