CWE-119
14,089 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,089)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially exist. |
In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist. |
In UIM in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist. |
In HDR in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist. |
In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist. |
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishan...Show more |
Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1Parser.cxx. |
1Digium 2Certified Asterisk Open SourceMay 13, 2026 Jun 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow an...Show more |
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully. |
In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value. |
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLA...Show more |
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote...Show more |
1Microsoft 3Forefront Security Malware Protection EngineWindows DefenderMay 13, 2026 May 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 3Forefront Security Malware Protection EngineWindows DefenderMay 13, 2026 May 26, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 3Forefront Security Malware Protection EngineWindows DefenderMay 13, 2026 May 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 3Forefront Security Malware Protection EngineWindows DefenderMay 13, 2026 May 26, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 7Endpoint Protection Exchange ServerForefront Endpoint Protection+4 moreMay 13, 2026 May 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 7Endpoint Protection Exchange ServerForefront Endpoint Protection+4 moreMay 13, 2026 May 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
1Microsoft 7Endpoint Protection Exchange ServerForefront Endpoint Protection+4 moreMay 13, 2026 May 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more |
Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c. |