CWE-119
14,089 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,089)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
2Apple Canonical4Iphone Os ItunesSafari+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an i...Show more |
4Canonical MozillaOpensuse+1 more5Firefox Firefox OsOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified o...Show more |
4Canonical MozillaOpensuse+1 more5Firefox Firefox OsOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly hav...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data. |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash...Show more |
3Mozilla OpensuseOracle3Firefox OpensuseSolarisMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cau...Show more |
4Canonical DebianMozilla+1 more4Debian Linux FirefoxOpensuse+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
Microsoft Office 2007 SP3, Office for Mac 2011, Office for Mac 2016, and Word Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." |
1Microsoft 2Windows Server 2008 Windows VistaMay 6, 2026 Aug 15, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 Microsoft Windows Vista SP2 and Server 2008 SP2 allow remote authenticated users to execute arbitrary code via a crafted string in a Server Message Block (SMB) server error-logging action, aka "Server Message Block Memor...Show more |
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." |
1Microsoft 7Office Office Compatibility PackSharepoint Server+4 moreMay 6, 2026 Aug 15, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office for Mac 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Serve...Show more |
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." |