CWE-119
14,088 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CVEs (14,088)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian Jasper ProjectOpensuse+1 more4Debian Linux Enterprise LinuxJasper+1 moreMay 6, 2026 Jan 26, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image. |
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file. |
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2...Show more |
The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote...Show more |
OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c. |
The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a deni...Show more |
5Canonical ChromiumGoogle+2 more8Chrome ChromiumEnterprise Linux Desktop Supplementary+5 moreMay 6, 2026 Jan 22, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. |
4Chromium GoogleOpensuse+1 more7Chrome ChromiumEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 Jan 22, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attacke...Show more |
The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. |
Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified...Show more |
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file. |
3Apple LibpngOracle3Libpng Mac Os XSolarisMay 6, 2026 Jan 18, 2015 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different...Show more |
1Ge 1Intelligent Platforms Proficy Hmi/scada Cimplicity May 6, 2026 Jan 17, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file. |
Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related...Show more |
Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related...Show more |
4Canonical DebianFedoraproject+1 more4Binutils Debian LinuxFedora+1 moreMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended nam...Show more |
1Adobe 4Adobe Air Adobe Air SdkAdobe Air Sdk And Compiler+1 moreMay 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before...Show more |
1Adobe 4Adobe Air Adobe Air SdkAdobe Air Sdk And Compiler+1 moreMay 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 8.5 HIGH· v2 Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe A...Show more |
1Adobe 4Adobe Air Adobe Air SdkAdobe Air Sdk And Compiler+1 moreMay 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before...Show more |
1Microsoft 7Windows 7 Windows 8Windows 8.1+4 moreMay 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote...Show more |