← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Polycom
3Group Series
HdxPano
Nov 21, 2024
May 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buff...Show more
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.Show less
1Asus
1Rt Ac3200 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.
1Denx
1U Boot
Jun 17, 2026
May 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
1Opto22
4Optodatalink
OptoopcserverPac Display+1 more
Nov 21, 2024
May 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, O...Show more
A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.Show less
1Qnap
1Myqnapcloud
Jun 17, 2026
May 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.
1Facebook
1Hhvm
Jun 17, 2026
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
1Dhcpcd Project
1Dhcpcd
Jun 17, 2026
Apr 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.
2Mozilla
Redhat
6Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+3 more
Jun 17, 2026
Apr 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunde...Show more
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Apr 26, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value i...Show more
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have explicitly disabled Spectre mitigations. *Note: Spectre mitigations are currently enabled for all users by default settings.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.Show less
1Verypdf
1Verypdf
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
VeryPDF 4.1 has a Memory Overflow leading to Code Execution because pdfocx!CxImageTIF::operator in pdfocx.ocx (used by pdfeditor.exe and pdfcmd.exe) is mishandled.
1Tenda
3Ac10 Firmware
Ac7 FirmwareAc9 Firmware
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffe...Show more
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.Show less
1Tenda
3Ac10 Firmware
Ac7 FirmwareAc9 Firmware
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffe...Show more
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.Show less
1Neatorobotics
1Botvac Connected Firmware
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a ve...Show more
A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a vendors/neato/robots/[robot_serial]/messages Neato cloud URI on the nucleo.neatocloud.com web site (port 4443).Show less
1Google
1Tensorflow
Nov 21, 2024
Apr 24, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.
1Google
1Tensorflow
Jun 17, 2026
Apr 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).
1Trendnet
1Tew 632brp Firmware
Jun 17, 2026
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface.
1Openplcproject
2Openplc V2 Firmware
Openplc V3 Firmware
Nov 21, 2024
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possi...Show more
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact.Show less
1Activision
1Call Of Duty
Nov 21, 2024
Apr 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine...Show more
SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.Show less
2Eclipse
Redhat
6Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
Jun 17, 2026
Apr 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and reje...Show more
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.Show less
2Mozilla
Sil
2Firefox
Graphite2
Nov 21, 2024
Apr 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.