← Back
CWE-119

14,089 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,089)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Outlook
May 13, 2026
Jun 15, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists in the way Microsoft Office software parses specially crafted email messages, aka "Microsoft Office Memory Corruption Vulnerability".
1Microsoft
1Edge
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user when the Edge JavaScript scripting engine fails to handle objects in memory, aka "Scripting Engine Memory...Show more
Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user when the Edge JavaScript scripting engine fails to handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8520, CVE-2017-8521, CVE-2017-8548, and CVE-2017-8549.Show less
1Microsoft
1Edge
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Mem...Show more
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8496.Show less
1Microsoft
1Edge
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Mem...Show more
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8497.Show less
1Digital Canal Structural
1Wind Analysis
May 13, 2026
Jun 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-...Show more
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-of-service attack.Show less
1Haxx
1Curl
May 13, 2026
Jun 14, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had...Show more
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given "URL" starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string "file://").Show less
1Google
1Android
May 13, 2026
Jun 14, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical du...Show more
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process.Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34064500.Show less
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WideVine DRM.
1Google
1Android
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.
1Tlslite Project
1Tlslite
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The tlslite library before 0.4.9 for Python allows remote attackers to trigger a denial of service (runtime exception and process crash).