CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,732 vulnerabilities with CWE-119
CVE-2026-22167
GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory
CVE-2026-7582 MEDIUM
AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write
CVSS 5.3
CVE-2026-7546 CRITICAL
Totolink NR1800X lighttpd find_host_ip stack-based overflow
CVSS 9.8
CVE-2026-7513 HIGH
UTT HiPER 1200GW formRemoteControl strcpy buffer overflow
CVSS 8.8
CVE-2026-7512 HIGH
UTT HiPER 1200GW formUser strcpy buffer overflow
CVSS 8.8
CVE-2026-7503 HIGH
code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow
CVSS 8.8
CVE-2026-7470 HIGH
Tenda 4G300 SafeMacFilter sub_427C3C stack-based overflow
CVSS 8.8
CVE-2026-7420 HIGH
UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow
CVSS 8.8
CVE-2026-7419 HIGH
UTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow
CVSS 8.8
CVE-2026-7418 HIGH
UTT HiPER 1250GW NTP strcpy buffer overflow
CVSS 8.8
CVE-2026-7346 HIGH
Google Chrome < 147.0.7727.138 - Out-of-Bounds Access
CVSS 8.1
CVE-2026-7324 HIGH
Memory safety bugs fixed in Firefox 150.0.1 and Thunderbird 150.0.1
CVSS 7.3
CVE-2026-7323 HIGH
Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1
CVSS 7.3
CVE-2026-7322 HIGH
Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1
CVSS 7.3
CVE-2026-7320 HIGH
Information disclosure due to incorrect boundary conditions in the Audio/Video component
CVSS 7.5
CVE-2026-7289 HIGH
D-Link DIR-825M formWanConfigSetup sub_414BA8 buffer overflow
CVSS 8.8
CVE-2026-7288 HIGH
D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow
CVSS 8.8
CVE-2026-7248 CRITICAL
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
CVSS 9.8
CVE-2026-7247 HIGH
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
CVSS 7.2
CVE-2026-7233 LOW
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
CVSS 3.3
CVE-2026-7219 HIGH
Totolink N300RT formIpQoS buffer overflow
CVSS 7.2
CVE-2026-7218 HIGH
Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow
CVSS 7.2
CVE-2026-7151 HIGH
Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow
CVSS 8.8
CVE-2026-7135 MEDIUM
GPAC MP4Box box_code_base.c elng_box_read out-of-bounds
CVSS 5.3
CVE-2026-7101 HIGH
Tenda F456 httpd WrlclientSet fromWrlclientSet buffer overflow
CVSS 8.8
Details
Vulnerabilities 13,732
Exploit Likelihood High