← Back
CWE-119

14,080 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

JSON object

Loading...

CVEs (14,080)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Office
Apr 29, 2026
Nov 13, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD File Format Memory Corruption Vulnerability."
1Linux
1Linux Kernel
Apr 29, 2026
Nov 12, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain...Show more
The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, a different vulnerability than CVE-2013-4511.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Nov 12, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Multiple buffer overflows in drivers/staging/wlags49_h2/wl_priv.c in the Linux kernel before 3.12 allow local users to cause a denial of service or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN c...Show more
Multiple buffer overflows in drivers/staging/wlags49_h2/wl_priv.c in the Linux kernel before 3.12 allow local users to cause a denial of service or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability and providing a long station-name string, related to the (1) wvlan_uil_put_info and (2) wvlan_set_station_nickname functions.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Nov 12, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted wri...Show more
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Nov 12, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Buffer overflow in the exitcode_proc_write function in arch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging roo...Show more
Buffer overflow in the exitcode_proc_write function in arch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging root privileges for a write operation.Show less
1Microsoft
10Windows 7
Windows 8Windows 8.1+7 more
Apr 22, 2026
Nov 12, 2013
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows...Show more
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."Show less
1Ibm
1Lotus Sametime
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
1Cisco
1Nx Os
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRR...Show more
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.Show less
1Cisco
1Ios Xr
Apr 29, 2026
Nov 8, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.
1Cisco
1Prime Central For Hosted Collaboration Solution
Apr 29, 2026
Nov 6, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313.
1Ibm
1Platform Symphony
Apr 29, 2026
Nov 6, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Buffer overflow in IBM Platform Symphony 5.2, 6.1, and 6.1.1 allows remote attackers to cause a denial of service (process crash or hang) via a malformed SOAP request with a large amount of request data.
1Cisco
1Prime Central For Hosted Collaboration Solution
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345.
1Cisco
1Anyconnect Secure Mobility Client
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML do...Show more
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Nov 4, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by se...Show more
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.Show less
1Xen
1Xen
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.
2Redhat
Spice Project
3Enterprise Linux
Enterprise VirtualizationSpice
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
1Strongswan
1Strongswan
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote...Show more
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349.
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device re...Show more
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN portal for internal-resource browsing, aka Bug ID CSCui51199.Show less
2Varnish Cache
Varnish Cache Project
2Varnish
Varnish Cache
Apr 29, 2026
Nov 1, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.