← Back
CWE-119

14,091 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,091)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1767.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1768.
1Apple
1Xcode
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.
6Apple
CanonicalDebian+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 6, 2026
Mar 24, 2016
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Mar 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The kernel in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a c...Show more
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a c...Show more
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1755.Show less
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1746.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a dif...Show more
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.Show less
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a dif...Show more
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1744.Show less
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF docume...Show more
FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.Show less
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
Carbon in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dfont file.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1735.
1Apple
1Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1736.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Mar 24, 2016
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted US...Show more
AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.Show less