← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7....Show more
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.Show less
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows...Show more
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6...Show more
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.Show less
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
1Apple
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
1Grandstream
5Gac2500 Firmware
Gvc3202 FirmwareGxp2200 Firmware+2 more
Jun 17, 2026
Mar 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manage...Show more
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.Show less
1Tp Link
1Tl Wr840n Firmware
Nov 21, 2024
Mar 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
4Canonical
DebianDovecot+1 more
4Debian Linux
DovecotLeap+1 more
Jun 17, 2026
Mar 28, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and...Show more
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.Show less
1Tianocore
1Edk Ii
Nov 21, 2024
Mar 27, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
1Faststone
1Image Viewer
Nov 21, 2024
Mar 26, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.
1Faststone
1Image Viewer
Nov 21, 2024
Mar 26, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.
1Faststone
1Image Viewer
Nov 21, 2024
Mar 26, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.