CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2022-40760 HIGH
Samsung mTower <= 0.3.0 - Denial of Service via TEE_MACUpdate Excessive Chunk Size
CVSS 7.5
CVE-2022-40758 HIGH
Samsung mTower <= 0.3.0 - Denial of Service via TEE_CipherUpdate Excessive Size Value
CVSS 7.5
CVE-2022-40757 HIGH
Samsung mTower <= 0.3.0 - Denial of Service via TEE_MACComputeFinal Excessive Message Length
CVSS 7.5
CVE-2022-3216 MEDIUM
Nintendo Game Boy Color - Memory Corruption
CVSS 5.0
CVE-2022-1778 HIGH
Hitachi Energy MicroSCADA X SYS600 10.0-10.3.1 - Authenticated Buffer Overflow via Configuration File
CVSS 7.5
CVE-2022-37302 MEDIUM
EcoStruxure Control Expert < 15.1 HF001 - Denial of Service via Malformed Project File
CVSS 5.5
CVE-2022-2964 HIGH
Linux Kernel >=4.20 <5.4.180 - Memory Corruption in ASIX AX88179_178A USB Ethernet Driver
CVSS 7.8
CVE-2022-36086 HIGH
linked_list_allocator <0.10.2 - Memory Corruption
CVSS 8.4
CVE-2022-25310 MEDIUM
Fribidi < 1.0.12 - Denial of Service via fribidi_remove_bidi_marks()
CVSS 5.5
CVE-2022-25658 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption in Video Parser Endianness Handling
CVSS 7.3
CVE-2022-22104 HIGH
Snapdragon Auto - Memory Corruption
CVSS 8.4
CVE-2022-22098 HIGH
Snapdragon Auto - Memory Corruption
CVSS 8.4
CVE-2022-1355 MEDIUM
libtiff < 4.4.0 - Stack Buffer Overflow in tiffcp via Crafted TIFF File
CVSS 6.1
CVE-2022-1115 MEDIUM
ImageMagick < 6.9.12-44 - Heap Buffer Overflow in PushShortPixel Function via TIFF Image Processing
CVSS 5.5
CVE-2022-0496 MEDIUM
OpenSCAD < 2022-02-04 - Memory Corruption via DXF Import
CVSS 5.5
CVE-2022-0367 HIGH
libmodbus < 3.1.7 - Heap-Based Buffer Overflow in modbus_reply()
CVSS 7.8
CVE-2022-32839 CRITICAL
macOS - Remote Code Execution via Improved Bounds Checks
CVSS 9.8
CVE-2022-34488 HIGH
Intel LAPBC510 and LAPBC710 Firmware < BC0076 - Privilege Escalation via Improper Buffer Restrictions
CVSS 7.8
CVE-2022-28858 HIGH
Intel(R) NUC Laptop Kits <BC0076 - Privilege Escalation
CVSS 7.8
CVE-2022-37770 MEDIUM
libjpeg - Denial of Service via Crafted File in LineMerger::GetNextLowpassLine
CVSS 6.5
CVE-2022-37769 MEDIUM
libjpeg - Denial of Service via HuffmanDecoder::Get
CVSS 6.5
CVE-2022-21160 HIGH
Intel Wireless AC and Wi-Fi 6/6E Firmware < 22.120 - Unauthenticated Denial of Service via Network Access
CVSS 7.5
CVE-2022-35486 MEDIUM
otfcc 0.10.4 - Use-After-Free via otfccdump
CVSS 6.5
CVE-2022-38161 HIGH
Gumstix Overo SBC - Info Disclosure
CVSS 7.5
CVE-2022-29465 CRITICAL
Accusoft ImageGear 20.0 - Out-of-Bounds Write via PSD Header Processing
CVSS 9.8
Details
Vulnerabilities 13,962
Exploit Likelihood High