← Back
CWE-119

14,090 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Internet Explorer
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"...Show more
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6048.Show less
1Microsoft
1Visio
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Microsoft Visio 2007 SP3 and 2010 SP2 allows remote attackers to execute arbitrary code via crafted UML data in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."
1Microsoft
9Windows 10
Windows 7Windows 8+6 more
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain pr...Show more
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."Show less
1Microsoft
2Jscript
Vbscript
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (mem...Show more
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted replace operation with a JavaScript regular expression, aka "Scripting Engine Memory Corruption Vulnerability."Show less
1Konicaminolta
1Ftp Utility
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.
1Konicaminolta
1Ftp Utility
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command.
1Apple
1Watch Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918.
1Apple
1Watch Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5919.
1Netbsd
1Tnftpd
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a craf...Show more
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The SMB implementation in the kernel in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2...Show more
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5830.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2...Show more
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5890.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5873, and CVE-2...Show more
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5873, and CVE-2015-5890.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5872, CVE-2015-5873, and CVE-2...Show more
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5872, CVE-2015-5873, and CVE-2015-5890.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.
1Google
1Android
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulner...Show more
libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.Show less
1Google
1Android
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23129786.