← Back
CWE-119

14,090 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Imagemagick
Opensuse
2Imagemagick
Leap
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE f...Show more
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
1Apng Disassembler Project
1Apng Disassembler
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
1Elfutils Project
1Elfutils
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a m...Show more
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.Show less
1Elfutils Project
1Elfutils
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELF file, which triggers a memory allocation failure.
1Cisco
1Iox
May 13, 2026
Mar 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution wi...Show more
A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution with root privileges in the virtual instance running on an affected device. The vulnerability is due to insufficient bounds checking in the DMo process. An attacker could exploit this vulnerability by sending crafted packets that are forwarded to the DMo process for evaluation. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. This vulnerability affects the following Cisco 800 Series Industrial Integrated Services Routers: Cisco IR809 and Cisco IR829. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52330.Show less
1Pngdefry Project
1Pngdefry
May 13, 2026
Mar 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the 'process()' function of the 'pngdefry.c' source...Show more
pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the 'process()' function of the 'pngdefry.c' source file.Show less
1Disksorter
1Disk Sorter
May 13, 2026
Mar 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.
1Gnu
1Binutils
May 13, 2026
Mar 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.
1Gnu
1Binutils
May 13, 2026
Mar 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted palm file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access).
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap overflow in ImageMagick 6.8.9-9 via a crafted wpf file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap overflow in ImageMagick 6.8.9-9 via a crafted pict file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap overflow in ImageMagick 6.8.9-9 via a crafted psd file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap overflow in ImageMagick 6.8.9-9 via a crafted pcx file.
1Gnu
1Binutils
May 13, 2026
Mar 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash.
1Gnu
1Binutils
May 13, 2026
Mar 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.