← Back
CWE-119

14,079 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,079)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Philips
5Pagewriter Tc10 Firmware
Pagewriter Tc20 FirmwarePagewriter Tc30 Firmware+2 more
Nov 21, 2024
Aug 22, 2018
N/A· v4
3.7 LOW· v3
4.6 MEDIUM· v2
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabili...Show more
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.Show less
4Canonical
DebianRedhat+1 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
Nov 21, 2024
Aug 22, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba vers...Show more
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.Show less
1Intel
1Lldptool
Nov 21, 2024
Aug 21, 2018
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the...Show more
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.Show less
1Emerson
1Deltav
Nov 21, 2024
Aug 21, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to allow arbitrary code execution.
1Surina
1Soundtouch
Nov 21, 2024
Aug 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack appear to be exploit...Show more
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack appear to be exploitable via victim must open maliocius file in soundstretch utility.Show less
1Pkgconf
1Pkgconf
Nov 21, 2024
Aug 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear...Show more
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.Show less
1Rust Lang
1Rust
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::V...Show more
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function that can result in Arbitrary code execution, but no proof-of-concept exploit is currently published.. This vulnerability appears to have been fixed in after commit fdfafb510b1a38f727e920dccbeeb638d39a8e60; stable release 1.22.0 and later.Show less
2Debian
Nongnu
2Debian Linux
Zutils
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim op...Show more
zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.Show less
1Kraftway
124f2xg Router Firmware
Nov 21, 2024
Aug 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Router firmware 3.5.30.1118.
1Kraftway
124f2xg Router Firmware
Nov 21, 2024
Aug 17, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118.
4Canonical
DebianRedhat+1 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
Nov 21, 2024
Aug 17, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send speci...Show more
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.Show less
1Yubico
3Piv Manager
Piv ToolSmart Card Minidriver
Nov 21, 2024
Aug 15, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `ykpiv_transfer_data()`: {% highlight c %} if(*out_len + recv_len - 2 > ma...Show more
A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `ykpiv_transfer_data()`: {% highlight c %} if(*out_len + recv_len - 2 > max_out) { fprintf(stderr, "Output buffer to small, wanted to write %lu, max was %lu.", *out_len + recv_len - 2, max_out); } if(out_data) { memcpy(out_data, data, recv_len - 2); out_data += recv_len - 2; *out_len += recv_len - 2; } {% endhighlight %} -- it is clearly checked whether the buffer is big enough to hold the data copied using `memcpy()`, but no error handling happens to avoid the `memcpy()` in such cases. This code path can be triggered with malicious data coming from a smartcard.Show less
1Tp Link
1Tl Wr840n Firmware
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
1Hikvision
1Ip Cameras
Jun 17, 2026
Aug 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can...Show more
A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can corrupt memory and lead to arbitrary code execution or crash the process.Show less
1Hp
2701dt61a Firmware
1jl02a Firmware1jl02b Firmware+267 more
Jun 17, 2026
Aug 13, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.
1Hotel Booking Script Project
1Hotel Booking Script
Nov 21, 2024
Aug 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Aug 10, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile.
1Cisco
1Thor Video Codec
Nov 21, 2024
Aug 9, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted n...Show more
Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream.Show less
1Xnview
1Xnview
Nov 21, 2024
Aug 8, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.
1Xnview
1Xnview
Nov 21, 2024
Aug 8, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a craft...Show more
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.Show less