CWE-119
14,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127 |
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array. |
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object. |
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the...Show more |
2Debian Xiph2Debian Linux IcecastNov 21, 2024 Nov 5, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted...Show more |
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file. |
1Yitechnology 2Yi Home Yi Home Camera FirmwareNov 21, 2024 Nov 1, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker...Show more |
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba...Show more |
2Debian Redhat5Debian Linux Enterprise Linux ServerEnterprise Linux Virtualization+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote a...Show more |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service. |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Phantom PDF 9.1.5096. User interaction is required to exploit this vulnerability in that the target mus...Show more |
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660 |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
1Qualcomm 2Sd 845 Firmware Sd 850 FirmwareNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
1Qualcomm 49Ipq4019 Firmware Ipq8064 FirmwareIpq8074 Firmware+46 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074,...Show more |