CWE-119
14,091 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,091)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Libreoffice2Libreoffice Ubuntu LinuxMay 6, 2026 Feb 18, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document. |
10Canonical DebianF5+7 more30Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+27 moreMay 6, 2026 Feb 18, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxMay 6, 2026 Feb 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 Feb 14, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (o...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 Feb 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attack...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote a...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxMay 6, 2026 Feb 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document. |
2Canonical Ffmpeg2Ffmpeg Ubuntu LinuxMay 6, 2026 Feb 12, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a c...Show more |
libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds array access) o...Show more |
libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain height values, which allows remote attackers to cause a denial of service (out-of-bounds array read access) or possibly have unspecified othe...Show more |
libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect line sizes in certain row calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other...Show more |
1Cisco 1Adaptive Security Appliance Software May 6, 2026 Feb 11, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4),...Show more |
1Adobe 2Bridge Cc Photoshop CcMay 6, 2026 Feb 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe...Show more |
1Adobe 2Bridge Cc Photoshop CcMay 6, 2026 Feb 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe...Show more |
1Adobe 2Bridge Cc Photoshop CcMay 6, 2026 Feb 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a diffe...Show more |
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." |
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"...Show more |
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." |