CWE-119
14,091 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,091)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and...Show more |
3Oracle QemuRedhat3Linux OpenstackQemuMay 6, 2026 Apr 7, 2016 N/A· v4 8.1 HIGH· v3 6.9 MEDIUM· v2 The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to ca...Show more |
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers. |
2Canonical Squid Cache2Squid Ubuntu LinuxMay 6, 2026 Apr 7, 2016 N/A· v4 8.2 HIGH· v3 7.5 HIGH· v2 Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or tra...Show more |
4Dell NetgearZyxel+1 more4Emc Powerscale Onefs Gs1900 10hp FirmwareJr6150 Firmware+1 moreMay 6, 2026 Apr 6, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malforme...Show more |
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page. |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CV...Show more |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CV...Show more |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CV...Show more |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CV...Show more |
The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of...Show more |
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have un...Show more |
3Debian FedoraprojectFuseiso Project3Debian Linux FedoraFuseisoMay 6, 2026 Mar 30, 2016 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathnam...Show more |
2Fedoraproject Fuseiso Project2Fedora FuseisoMay 6, 2026 Mar 30, 2016 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF bl...Show more |
4Canonical DebianGoogle+1 more4Chrome Debian LinuxOpensuse+1 moreMay 6, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial o...Show more |
Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a c...Show more |
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other i...Show more |
2Apple Webkitgtk4Iphone Os SafariTvos+1 moreMay 6, 2026 Mar 24, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Mar 24, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font f...Show more |
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop file. |