← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GnuplotOpensuse
3Debian Linux
GnuplotLeap
Nov 21, 2024
Nov 23, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of...Show more
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.Show less
1Armcode
1Adult Filter
Nov 21, 2024
Nov 22, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.
1Contiki Ng
1Contiki Ng.
Nov 21, 2024
Nov 21, 2018
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy to input data into a fixed size buffer. T...Show more
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy to input data into a fixed size buffer. The allocated buffer can fit only MQTT_MAX_TOPIC_LENGTH (default 64) bytes, and a length check is missing. This could lead to Remote Code Execution via a stack-smashing attack (overwriting the function return address). Contiki-NG does not separate the MQTT server from other servers and the OS modules, so access to all memory regions is possible.Show less
1Microfocus
1Netware
Nov 21, 2024
Nov 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was...Show more
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.Show less
1Pcman Ftp Server Project
1Pcman Ftp Server
Nov 21, 2024
Nov 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
1Denx
1U Boot
Nov 21, 2024
Nov 20, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.
1Denx
1U Boot
Nov 21, 2024
Nov 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
1Modbustools
1Modbus Slave
Nov 21, 2024
Nov 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
1Kangujang
1Local Server
Nov 21, 2024
Nov 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.
1Neo
2Debun Imap
Debun Pop
Nov 21, 2024
Nov 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) cond...Show more
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.Show less
1Neo
2Debun Imap
Debun Pop
Nov 21, 2024
Nov 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) cond...Show more
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.Show less
1Digium
1Asterisk
Nov 21, 2024
Nov 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size...Show more
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.Show less
1Google
1Android
Jun 17, 2026
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interactio...Show more
In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112766520Show less
1Microsoft
1Internet Explorer
Jun 17, 2026
Nov 14, 2018
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windo...Show more
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.Show less
1Microsoft
4Windows Server 2008
Windows Server 2012Windows Server 2016+1 more
Jun 17, 2026
Nov 14, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affe...Show more
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.Show less
1Losant
1Arduino Mqtt Client
Nov 21, 2024
Nov 13, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT Client prior to V2.7. User interaction is not required to exploit this vulnerability. The specific f...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Losant Arduino MQTT Client prior to V2.7. User interaction is not required to exploit this vulnerability. The specific flaw exists within the parsing of MQTT PUBLISH packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6436.Show less
1Sass Lang
1Libsass
Nov 21, 2024
Nov 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In LibSass 3.5-stable, there is an illegal address access at Sass::Eval::operator that will lead to a DoS attack.
1Ethereumjs Vm Project
1Ethereumjs Vm
Nov 21, 2024
Nov 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute. NOTE: the vendor disputes this because REVERT is a normal bytecode th...Show more
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute. NOTE: the vendor disputes this because REVERT is a normal bytecode that can be triggered from high-level source code, leading to a normal programmatic execution result.Show less
1Ethereum
1Py Evm
Nov 21, 2024
Nov 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting in an execution failure because of an i...Show more
Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting in an execution failure because of an invalid opcode. This is reportedly related to "smart contracts can be executed indefinitely without gas being paid."Show less
1Pdfforge
1Pdf Architect
Nov 21, 2024
Nov 10, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Da...Show more
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.Show less