← Back
CWE-119

14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,075)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libav
1Libav
Nov 21, 2024
Nov 9, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127
1Omron
1Cx Supervisor
Nov 21, 2024
Nov 5, 2018
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
1Omron
1Cx Supervisor
Nov 21, 2024
Nov 5, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.
1Suricata Ids
1Suricata
Nov 21, 2024
Nov 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the...Show more
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.Show less
2Debian
Xiph
2Debian Linux
Icecast
Nov 21, 2024
Nov 5, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted...Show more
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.Show less
1M2soft
1Report Designer
Nov 21, 2024
Nov 1, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
1Yitechnology
2Yi Home
Yi Home Camera Firmware
Nov 21, 2024
Nov 1, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker...Show more
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker can make the camera scan a QR code to trigger this vulnerability. Alternatively, a user could be convinced to display a QR code from the internet to their camera, which could exploit this vulnerability.Show less
1Samba
1Samba
Nov 21, 2024
Nov 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba...Show more
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.Show less
2Debian
Redhat
5Debian Linux
Enterprise Linux ServerEnterprise Linux Virtualization+2 more
Nov 21, 2024
Oct 31, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote a...Show more
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.Show less
3Canonical
DebianHaxx
3Curl
Debian LinuxUbuntu Linux
Nov 21, 2024
Oct 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.
1Foxitsoftware
1Phantompdf
Nov 21, 2024
Oct 29, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Phantom PDF 9.1.5096. User interaction is required to exploit this vulnerability in that the target mus...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Phantom PDF 9.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within fxhtml2pdf. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6230.Show less
1Advantech
1Webaccess
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
1Qualcomm
2Sd 845 Firmware
Sd 850 Firmware
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.
1Qualcomm
4Sd 835 Firmware
Sd 845 FirmwareSd 850 Firmware+1 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
1Qualcomm
49Ipq4019 Firmware
Ipq8064 FirmwareIpq8074 Firmware+46 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074,...Show more
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016.Show less