← Back
CWE-119

14,086 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,086)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianFile Project+2 more
5Debian Linux
FileOpensuse+2 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
2Mutt
Opensuse
2Mutt
Opensuse
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
4Canonical
DebianFedoraproject+1 more
4Cups Filters
Debian LinuxFedora+1 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
2Canonical
Linuxfoundation
2Cups Filters
Ubuntu Linux
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1294.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen...Show more
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafte...Show more
The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in ImageIO in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
1Yokogawa
1Centum Cs 3000
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
1Yokogawa
1Centum Cs 3000
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
1Yokogawa
1Centum Cs 3000
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
1Aveva
1Clearscada
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72...Show more
The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build 73.4955, and 2013 R2 build 74.5094 allows remote attackers to cause a denial of service (application crash) via a crafted OPF file (aka project file).Show less
1Adobe
1Shockwave Player
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
1Freetype
1Freetype
May 6, 2026
Mar 12, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number...Show more
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Mar 12, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"...Show more
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0312.Show less