CWE-119
14,091 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,091)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file. |
1Unitronics 1Visilogic Oplc Ide May 6, 2026 Jun 25, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a ZIP archive in a vlp file. |
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager p...Show more |
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulner...Show more |
Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132. |
1Cisco 3Rv110w Wireless N Vpn Firewall Firmware Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router FirmwareMay 6, 2026 Jun 19, 2016 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote auth...Show more |
4Debian FfmpegLibav+1 more4Debian Linux FfmpegLeap+1 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dr...Show more |
1Adobe 1Dng Software Development Kit May 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption...Show more |
1Microsoft 2Excel Office Compatibility PackMay 6, 2026 Jun 16, 2016 N/A· v4 7.3 HIGH· v3 9.3 HIGH· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." |
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." |
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerabil...Show more |
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"...Show more |
The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scriptin...Show more |
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corr...Show more |
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corr...Show more |