CWE-119
14,080 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,080)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A buffer overflow in Handy Password 4.9.3 allows remote attackers to execute arbitrary code via a long "Title name" field in "mail box" data that is mishandled in an "Open from mail box" action. |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow. |
1Intel 1Driver & Support Assistant Nov 21, 2024 Jan 9, 2018 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service...Show more |
1Rockwellautomation 61766 L32awa Firmware 1766 L32awaa Firmware1766 L32bwa Firmware+3 moreNov 21, 2024 Jan 9, 2018 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, whic...Show more |
1Barcodewiz 1Barcode Activex Control Nov 21, 2024 Jan 9, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property. |
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted...Show more |
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted...Show more |
2Debian Irssi2Debian Linux IrssiNov 21, 2024 Jan 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. |
In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrato...Show more |
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple instances of a vulnerability that allows too much data to be written to a location on the stack. |
1Cisco 4Webex Business Suite Webex MeetingsWebex Meetings Server+1 moreNov 21, 2024 Jan 4, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit...Show more |
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecif...Show more |
Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution. |
1Rust Base64 Project 1Rust Base64 Nov 21, 2024 Jan 2, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Jan 2, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations. |
The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspec...Show more |
2Debian Opencv2Debian Linux OpencvMay 13, 2026 Dec 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used. |
1Xi Soft 1Nettransport Download Manager May 13, 2026 Dec 29, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response. |
1Allmediaserver 1Allmediaserver May 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/comp...Show more |
1Mozilla 1Network Security Services May 13, 2026 Dec 27, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file. |