← Back
CWE-119

14,090 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Podofo Project
1Podofo
May 13, 2026
Mar 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.
1Fatek
4Ethernet Module Configuration Tool Cbe Firmware
Ethernet Module Configuration Tool Cbeh FirmwareEthernet Module Configuration Tool Cm25e Firmware+1 more
May 13, 2026
Mar 16, 2017
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 B...Show more
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.Show less
2Debian
Osgeo
2Debian Linux
Mapserver
May 13, 2026
Mar 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors inv...Show more
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.Show less
1Broadcom
1Tcpreplay
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the tcpcapinfo utility in Tcpreplay before 4.2.0 Beta 1 allows remote attackers to have unspecified impact via a pcap file with an over-size packet.
1Virglrenderer Project
1Virglrenderer
May 13, 2026
Mar 15, 2017
N/A· v4
7.1 HIGH· v3
2.1 LOW· v2
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted tex...Show more
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.Show less
1Easycom Aura
1Easycom For Php
May 13, 2026
Mar 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect...Show more
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.Show less
1Jasper Project
1Jasper
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
1Podofo Project
1Podofo
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.
1Podofo Project
1Podofo
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.
1Audiofile
1Audiofile
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file.
1Audiofile
1Audiofile
May 13, 2026
Mar 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audi...Show more
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file.Show less
1Libplist Project
1Libplist
May 13, 2026
Mar 15, 2017
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.
1Libplist Project
1Libplist
May 13, 2026
Mar 15, 2017
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.
1Virglrenderer Project
1Virglrenderer
May 13, 2026
Mar 15, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-o...Show more
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties.Show less
1Virglrenderer Project
1Virglrenderer
May 13, 2026
Mar 15, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and cra...Show more
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.Show less
1Adobe
2Flash Player
Flash Player Desktop Runtime
May 13, 2026
Mar 14, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbi...Show more
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution.Show less
2Asus
Trendnet
2Rt Ac66u Firmware
Tew 812dru Firmware
May 13, 2026
Mar 14, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU...Show more
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.Show less
1Hikvision
2Ds 76xxx Series Firmware
Ds 77xxx Series Firmware
May 13, 2026
Mar 13, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the SDK issue.
1Hikvision
2Ds 76xxx Series Firmware
Ds 77xxx Series Firmware
May 13, 2026
Mar 13, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the ISAPI issue...Show more
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the ISAPI issue.Show less
1Hikvision
2Ds 76xxx Series Firmware
Ds 77xxx Series Firmware
May 13, 2026
Mar 13, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the PSIA issue.