← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Faststone
1Image Viewer
Nov 21, 2024
Mar 26, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.
1Verifone
1Verix Multi App Conductor
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able t...Show more
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability.Show less
1Honeywell
1Experion Process Knowledge System
Nov 21, 2024
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible r...Show more
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.Show less
1Honeywell
1Experion Process Knowledge System
Nov 21, 2024
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remot...Show more
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.Show less
1Opto22
4Optodatalink
OptoopcserverPac Display+1 more
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.400...Show more
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC Display Professional versions prior to R9.4g, OptoOPCServer version R9.4c and prior that were installed by PAC Project installer, versions prior to R9.4008, and OptoDataLink version R9.4d and prior that were installed by PAC Project installer, versions prior to R9.4008. Opto 22 suggests upgrading to the new product version as soon as possible.Show less
1Xnview
1Xnview Classic
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.
1Xnview
1Xnview Classic
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.
1Xnview
1Xnview Classic
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.
1Xnview
1Xnview Classic
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.
1Xnview
1Xnview Mp
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap.
1Xnview
1Xnview Mp
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlpNtMakeTemporaryKey.
1Xnview
1Xnview Mp
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap.
1Xnview
1Xnview Mp
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy.
1Moxa
1Softcms
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
1Moxa
1Softcms
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
2Fedoraproject
Putty
2Fedora
Putty
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
1Entrepreneur Job Portal Script Project
1Entrepreneur Job Portal Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via crafted JavaScript code in the KeySkills field.
1Chartered Accountant \
1 Auditor Website Project
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
1Advance B2b Script Project
1Advance B2b Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field.
2Debian
Yubico
2Debian Linux
Libu2f Host
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device...Show more
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.Show less