← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Swiftnio
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation.
2Apple
Canonical
7Icloud
Iphone OsItunes+4 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
1Apple
1Mac Os X
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.
1Apple
1Mac Os X
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.
1Apple
4Apple Tv
Iphone OsMac Os X+1 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was add...Show more
In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling.Show less
1Apple
4Icloud
Iphone OsItunes+1 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
1Apple
1Iphone Os
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.
1Panasonic
1Bn Sdwbp3 Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Buffer overflow in BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to execute arbitrary code via unspecified vectors.
1Mnc
1Inplc Rt
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may result in executing arbtrary code via unspecified vectors.
1Yokogawa
5Astplanner
Idefine For Prosafe Rs FirmwareStardom Fcn/fcj Simulator Firmware+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earli...Show more
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function or execute an arbitrary program via unspecified vectors.Show less
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.
1Nec
1Aterm W300p Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.
1Nec
1Aterm W300p Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and response.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
1Webroot
1Brightcloud
Nov 21, 2024
Jan 3, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code exe...Show more
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.Show less
1Minishare Project
1Minishare
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued.
1Minishare Project
1Minishare
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.
1Driveagent
1Driveagent
Nov 21, 2024
Jan 3, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrit...Show more
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrite the next pool header if there is one next to the user buffer's pool.Show less
1Freebsd
1Freebsd
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a boot...Show more
In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a stack buffer overflow. It is possible that the buffer overflow could lead to a Denial of Service or remote code execution.Show less