CWE-119
14,088 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,088)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in the Tiny SRP library (aka TinySRP) allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted size value for the username field. |
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via...Show more |
1Ca 6Client Automation Network And Systems ManagementNsm Job Management Option+3 moreMay 6, 2026 Jun 17, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Manageme...Show more |
3Canonical FfmpegLibav3Ffmpeg LibavUbuntu LinuxMay 6, 2026 Jun 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message...Show more |
3Opensuse RedhatW1.fi7Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+4 moreMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (cras...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length,...Show more |
2Openssl Oracle2Openssl Sparc Opl Service ProcessorMay 6, 2026 Jun 12, 2015 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read a...Show more |
The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpe...Show more |
The chmd_read_headers function in chmd.c in libmspack before 0.5 does not validate name lengths, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file. |
2Adobe Google5Air Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe A...Show more |
2Adobe Google5Air Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.1...Show more |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreApr 22, 2026 Jun 10, 2015 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi...Show more |
1Microsoft 2Windows 2003 Server Windows Server 2003May 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Memory C...Show more |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, a...Show more |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, a...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted len...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspe...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application...Show more |