← Back
CWE-119

14,090 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libtiff
1Libtiff
May 13, 2026
Mar 24, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "WRITE of size 2048" and libtiff/tif_next.c:6...Show more
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "WRITE of size 2048" and libtiff/tif_next.c:64:9.Show less
1Libtiff
1Libtiff
May 13, 2026
Mar 24, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "REA...Show more
tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 1" and libtiff/tif_fax3.c:413:13.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.
2Gnu
Opensuse
2Gnutls
Leap
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
2Gnu
Opensuse
2Gnutls
Leap
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
1Artifex
1Mujs
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments to lightweight functi...Show more
Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments to lightweight functions.Show less
1Libgit2 Project
1Libgit2
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a cr...Show more
Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.Show less
1Pcre
1Pcre
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact...Show more
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.Show less
1Pcre
1Pcre
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact vi...Show more
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.Show less
3Debian
ImagemagickOpensuse Project
3Debian Linux
ImagemagickLeap
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
1Libming
1Libming
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
1Wvware
1Libwmf
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.
1Jasper Project
1Jasper
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file...Show more
Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the WritePDBImage function in coders/pdb.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the WriteMAPImage function in coders/map.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.