← Back
CWE-119

14,087 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,087)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, a...Show more
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.Show less
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID C...Show more
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.Show less
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to execute arbitrary code via crafted DNS response packets, aka Bug ID CSCty44804.
1Coreftp
1Core Ftp
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read...Show more
Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read.Show less
6Canonical
FedoraprojectMozilla+3 more
7Fedora
FirefoxOpensuse+4 more
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds w...Show more
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.Show less
1F5
1Nginx
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
1Adobe
1Flash Player
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecifi...Show more
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt d...Show more
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.Show less
1Acunetix
1Web Vulnerability Scanner
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute).
1Powersoftware
1Winarchiver
May 6, 2026
Apr 25, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
1Debian
1Ppthtml
May 6, 2026
Apr 25, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .ppt file.
1Symantec
2Encryption Desktop
Pgp Desktop
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access vi...Show more
Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.Show less
1Symantec
2Encryption Desktop
Pgp Desktop
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access viola...Show more
Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.Show less
1Apple
1Mac Os X
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
1Cisco
1Ios
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809.
1Cisco
1Ios
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.
1Libmms Project
1Libmms
May 6, 2026
Apr 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execute arbitrary code via a long line in an MMS over HTTP (MMSH) server response.
2Fedoraproject
Json C
2Fedora
Json C
May 6, 2026
Apr 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.
1Uclouvain
1Openjpeg
May 6, 2026
Apr 18, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib/openjp3d/event.c.
1Nullsoft
1Winamp
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory nam...Show more
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.Show less