CWE-119
14,087 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,087)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The ddr_devfreq driver in versions earlier than GRA-UL00C00B197 has buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into installing a malicious application on th...Show more |
1Huawei 5Gt3 Firmware Honor 5c FirmwareKnt Firmware+2 moreMay 13, 2026 Nov 22, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The goldeneye driver in NMO-L31C432B120 and earlier versions,NEM-L21C432B100 and earlier versions,NEM-L51C432B120 and earlier versions,KNT-AL10C746B160 and earlier versions,VNS-L21C185B142 and earlier versions,CAM-L21C10...Show more |
The emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions has a buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into ins...Show more |
3Asus IntelSiemens198Active Management Technology Firmware B150 A FirmwareB150 Plus Firmware+195 moreMay 13, 2026 Nov 21, 2017 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code w...Show more |
3Asus IntelSiemens198Active Management Technology Firmware B150 A FirmwareB150 Plus Firmware+195 moreMay 13, 2026 Nov 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code...Show more |
1Intel 1Trusted Execution Engine Firmware May 13, 2026 Nov 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code. |
1Intel 1Server Platform Services Firmware May 13, 2026 Nov 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code. |
1Intel 1Manageability Engine Firmware May 13, 2026 Nov 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code. |
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot. |
The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability...Show more |
Exiv2 0.26 contains a heap buffer overflow in tiff parser |
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution |
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host. |
2Debian Teluu2Debian Linux PjsipMay 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing u...Show more |
p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted Mach-O file, related to canPack and unpack...Show more |
1Tcmu Runner Project 1Tcmu Runner May 13, 2026 Nov 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service |
picoTCP (versions 1.7.0 - 1.5.0) is vulnerable to stack buffer overflow resulting in code execution or denial of service attack |
In SWFTools, an address access exception was found in pdf2swf. FoFiTrueType::writeTTF() |
In SWFTools, a stack overflow was found in pdf2swf. |
In SWFTools, a memcpy buffer overflow was found in gif2swf. |