← Back
CWE-119

14,088 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,088)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Apr 15, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1...Show more
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1898.Show less
1Lhaplus
1Lhaplus
May 6, 2026
Apr 15, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in Lhaplus before 1.70 allows remote attackers to execute arbitrary code via a crafted archive.
4Adobe
OpensuseRedhat+1 more
8Enterprise Linux Desktop Supplementary
Enterprise Linux Server SupplementaryEnterprise Linux Server Supplementary Eus+5 more
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors.
1Das Watchdog Project
1Das Watchdog
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in das_watchdog 0.9.0 allows local users to execute arbitrary code with root privileges via a large string in the XAUTHORITY environment variable.
1Debian
2Dbd Firebird
Debian Linux
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related...Show more
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.Show less
2Gnu
Opensuse
2Less
Opensuse
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibtasn1+1 more
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
1Apple
1Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.
1Apple
1Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a craf...Show more
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
iWork in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.
3Arj Software
DebianFedoraproject
3Arj Archiver
Debian LinuxFedora
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
2Canonical
Gnu
2Glibc
Ubuntu Linux
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow...Show more
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.Show less
2Canonical
Gnu
2Glibc
Ubuntu Linux
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denia...Show more
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.Show less
1Ibm
1Domino
May 6, 2026
Apr 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and 9.0.1 before FP2 IF3 allows remote attackers to execute arbitrary code...Show more
Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and 9.0.1 before FP2 IF3 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Hidemaru
1Editor
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Saitoh Kikaku Maruo Editor 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted .hmbook file.
1Schneider Electric
1Vampset
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.
1Sap
1Afaria
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.
1Sap
1Netweaver
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute...Show more
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369.Show less
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly ha...Show more
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.Show less