← Back
CWE-119

14,088 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,088)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libid3tag Project
1Libid3tag
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
1Xiph
1Libao
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
1Xiph
1Vorbis Tools
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
1Openexif Project
1Openexif
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted jpg file.
2Debian
Libming
2Debian Linux
Ming
May 13, 2026
Jul 29, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
1Nvidia
1Gpu Driver
May 13, 2026
Jul 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect calculation of string length may lead to denial of service.
1Mediacoderhq
1Audiocoder
May 13, 2026
Jul 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
1Avira
1Antivirus
May 13, 2026
Jul 27, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based...Show more
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.Show less
1Mediacoder
1Mediacoder
May 13, 2026
Jul 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
1D.r.commander
1Libjpeg Turbo
May 13, 2026
Jul 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a craft...Show more
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse of the libjpeg APIShow less
1Lame Project
1Lame
May 13, 2026
Jul 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
1Acunetix
1Web Vulnerability Scanner
May 13, 2026
Jul 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess."
1Artifex
1Ghostscript Ghostxps
May 13, 2026
Jul 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (Segmentation Violation and application crash) via a crafted file.
1Artifex
1Ghostscript Ghostxps
May 13, 2026
Jul 26, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact...Show more
The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted document.Show less
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Jul 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 26, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/tiff.c.
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Jul 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
1Php
1Php
May 13, 2026
Jul 25, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing cod...Show more
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string or parse_ini_file function, e.g., a web application for syntax validation of php.ini directives.Show less
1Cisco
20Webex Event Center
Webex Meeting CenterWebex Meetings+17 more
May 13, 2026
Jul 25, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected...Show more
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.Show less
1Cisco
1Asr 5000 Series Software
May 13, 2026
Jul 25, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to a...Show more
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927.Show less