CWE-119
14,088 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,088)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 5Acrobat Acrobat DcAcrobat Reader+2 moreMay 13, 2026 Aug 11, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when proc...Show more |
1Adobe 5Acrobat Acrobat DcAcrobat Reader+2 moreMay 13, 2026 Aug 11, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when proc...Show more |
1Adobe 5Acrobat Acrobat DcAcrobat Reader+2 moreMay 13, 2026 Aug 11, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation...Show more |
1Adobe 5Acrobat Acrobat DcAcrobat Reader+2 moreMay 13, 2026 Aug 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing, where the font is e...Show more |
1Adobe 5Acrobat Acrobat DcAcrobat Reader+2 moreMay 13, 2026 Aug 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability that occurs when reading a JPEG file emb...Show more |
In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow...Show more |
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". |
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possibl...Show more |
Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". |
The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary fil...Show more |
Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in th...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tre...Show more |
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36998372. |
A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928. |
1Samsung 1Galaxy S6 Edge Firmware May 13, 2026 Aug 9, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a denial of service (segmentation fault and process crash) and execute a...Show more |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors. |
1Asuswrt Merlin 1Asuswrt Merlin May 13, 2026 Aug 9, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT...Show more |
1Microsoft 2Windows 7 Windows Server 2008May 13, 2026 Aug 8, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow an attacker to execute code remotely on a target system when the Windows font library fails to properly handle specially crafted embedded fonts, aka "Express Co...Show more |
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in...Show more |
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines re...Show more |