← Back
CWE-119

14,091 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,091)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foxitsoftware
2Foxit Reader
Phantompdf
May 6, 2026
Apr 22, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafte...Show more
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.Show less
2Giflib Project
Opensuse
2Giflib
Opensuse
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.
2Cairographics
Opensuse
2Cairo
Opensuse
May 6, 2026
Apr 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length.
1Honeywell
1Uniformance Process History Database
May 6, 2026
Apr 21, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.
1Cisco
14Adaptive Security Appliance Software
Dx Series Ip Phones FirmwareIos Xe+11 more
May 6, 2026
Apr 21, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
2Canonical
Optipng Project
2Optipng
Ubuntu Linux
May 6, 2026
Apr 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
1Tibco
2Enterprise Message Service
Enterprise Message Service Appliance Firmware
May 6, 2026
Apr 20, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and EMS Appliance before 2.4.0 allows remote authenticated users to cause a denial of service or possibly execute arbitrary...Show more
Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and EMS Appliance before 2.4.0 allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via crafted inbound data.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
OpensuseUbuntu Linux+1 more
May 6, 2026
Apr 19, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
5Canonical
FedoraprojectGnu+2 more
9Fedora
GlibcLinux Enterprise Debuginfo+6 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.Show less
2Libtiff
Opensuse
2Libtiff
Opensuse
May 6, 2026
Apr 19, 2016
N/A· v4
6.2 MEDIUM· v3
5.0 MEDIUM· v2
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
2Canonical
Videolan
2Ubuntu Linux
Vlc Media Player
May 6, 2026
Apr 18, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across E...Show more
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."Show less
1Opensuse
1Opensuse
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...Show more
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently b...Show more
media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26324358.Show less
2Dhcpcd Project
Google
2Android
Dhcpcd
May 6, 2026
Apr 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitra...Show more
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response, aka internal bug 26461634.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
8.4 HIGH· v3
10.0 HIGH· v2
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memor...Show more
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25818142.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to...Show more
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26040840.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
8.4 HIGH· v3
10.0 HIGH· v2
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via...Show more
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26399350.Show less