CWE-119
14,080 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,080)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get <node_name att...Show more |
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the p...Show more |
1Schneider Electric 1Triconex Tricon Mp 3008 Firmware Jun 17, 2026 May 4, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could all...Show more |
1Schneider Electric 1Triconex Tricon Mp 3008 Firmware Jun 17, 2026 May 4, 2018 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to g...Show more |
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'read <node_name>'...Show more |
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by a...Show more |
1Partclone Project 1Partclone Nov 21, 2024 May 2, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An attacker may be able...Show more |
partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to execute arbitrary code in the context...Show more |
1Cisco 1Wireless Lan Controller Software Nov 21, 2024 May 2, 2018 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to...Show more |
Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device...Show more |
1Huawei 6Dp300 Firmware Rp200 FirmwareTe30 Firmware+3 moreNov 21, 2024 Apr 30, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an invalid memory acc...Show more |
2Debian Wavpack2Debian Linux WavpackNov 21, 2024 Apr 29, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks. |
1We Con 3Levistudio Hmi Editor LevistudiouPi Studio Hmi Project ProgrammerJun 17, 2026 Apr 26, 2018 N/A· v4 5.3 MEDIUM· v3 6.8 MEDIUM· v2 A buffer overflow can be triggered in LeviStudio HMI Editor, Version 1.10 part of Wecon LeviStudioU 1.8.29, and PI Studio HMI Project Programmer, Build: November 11, 2017 and prior by opening a specially crafted file. |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Apr 24, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the BITMAPINFOHEADER record in BMP files. The issue results from the lack of proper validation of the biSize member, which c...Show more |
Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call. |
2Debian Libsdl2Debian Linux Sdl ImageNov 21, 2024 Apr 24, 2018 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trig...Show more |
2Debian Libsdl2Debian Linux Sdl ImageNov 21, 2024 Apr 24, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can displ...Show more |
An memory corruption vulnerability exists in the .PCX parsing functionality of Computerinsel Photoline 20.02. A specially crafted .PCX file can cause a vulnerability resulting in potential code execution. An attacker can...Show more |
1Tinysvcmdns Project 1Tinysvcmdns Nov 21, 2024 Apr 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap overflow vulnerability exists in the tinysvcmdns library version 2016-07-18. A specially crafted packet can make the library overwrite an arbitrary amount of data on the heap with attacker controlled...Show more |
An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential co...Show more |