CWE-119
14,090 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,090)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrar...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The AcroForm plugin in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attac...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrar...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrar...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrar...Show more |
1Microsoft 4Excel Excel For MacExcel Viewer+1 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary...Show more |
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Scripting Engine Memory Corruption Vulnerability." |
1Microsoft 7Windows 10 Windows 7Windows 8+4 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbit...Show more |
1Microsoft 5Excel For Mac OfficePowerpoint For Mac+2 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac...Show more |
Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." |
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scri...Show more |
2Apple Nghttp25Iphone Os Mac Os XNghttp2+2 moreMay 6, 2026 Jan 12, 2016 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug. |
Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before...Show more |
1F5 1Big Ip Access Policy Manager May 6, 2026 Jan 12, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors related to processing a Cit...Show more |
1Huawei 2Mate 7 Firmware P8 FirmwareMay 6, 2026 Jan 12, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 a...Show more |
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different v...Show more |
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different v...Show more |
1Unitronics 1Visilogic Oplc Ide May 6, 2026 Jan 9, 2016 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename. |
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085...Show more |
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a m...Show more |