CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2021-22426 CRITICAL
Huawei EMUI - Memory Corruption
CVSS 9.8
CVE-2021-46598 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-3657 CRITICAL
isync < 1.4.4 - Remote Code Execution via Large IMAP Literal Handling
CVSS 9.8
CVE-2021-20325 CRITICAL
Red Hat Enterprise Linux 8.5.0 - Security Regression via Missing httpd Fixes
CVSS 9.8
CVE-2021-46461 CRITICAL
njs < 0.7.0 - Out-of-Bounds Array Access in njs_vmcode_typeof
CVSS 9.8
CVE-2021-39997 CRITICAL
Huawei EMUI - Out-of-Bounds Access via Audio Assembly Input Parameter
CVSS 9.8
CVE-2021-46157 HIGH
Simcenter Femap <V2020.2, V2021.1 - Memory Corruption
CVSS 7.8
CVE-2021-46153 HIGH
Simcenter Femap V2020.2-V2021.1 - Memory Corruption
CVSS 7.8
CVE-2021-44018 HIGH
Siemens JT2Go < 13.2.0.7 - Memory Corruption via Crafted PAR File Parsing
CVSS 7.8
CVE-2021-44016 HIGH
Siemens JT2Go < 13.2.0.7 - Memory Corruption via Crafted PAR File
CVSS 7.8
CVE-2021-41839 HIGH
InsydeH2O 5.1-5.5 - Untrusted Pointer Dereference in NvmExpressDxe
CVSS 8.2
CVE-2021-41838 HIGH
InsydeH2O 5.1-5.5 - Unauthenticated Arbitrary Code Execution via SMM Callout
CVSS 8.2
CVE-2021-41837 HIGH
Insyde InsydeH2O 5.0-5.5 - Untrusted Pointer Dereference in AhciBusDxe
CVSS 8.2
CVE-2021-33627 HIGH
Insyde InsydeH2O Kernel <5.5 - Memory Corruption
CVSS 8.2
CVE-2021-33625 HIGH
InsydeH2O Kernel 5.x - Use After Free
CVSS 7.5
CVE-2021-31617 CRITICAL
Stormshield Network Security <=4.2.2 - Remote Code Execution via ASQ Memory Mishandling
CVSS 9.8
CVE-2021-44992 MEDIUM
Jerryscript 3.0.0 - Assertion Failure in ecma-typedarray-object.c
CVSS 5.5
CVE-2021-36343 HIGH
Dell Alienware BIOS Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-36342 HIGH
Dell Alienware BIOS Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2021-46333 MEDIUM
Moddable SDK v11.5.0 - Memory Corruption
CVSS 5.5
CVE-2021-46020 HIGH
mruby 3.0.0 - Untrusted Pointer Dereference in mrb_vm_exec()
CVSS 7.5
CVE-2021-45767 MEDIUM
GPAC 1.1.0 - Denial of Service via lsr_read_id() Function
CVSS 5.5
CVE-2021-45764 MEDIUM
GPAC 1.1.0 - Memory Corruption via shift_chunk_offsets.isra()
CVSS 5.5
CVE-2021-45067 MEDIUM
Adobe Acrobat and Reader DC < 21.007.20099 & < 17.011.30204 - Memory Access After Buffer End
CVSS 5.5
CVE-2021-44712 MEDIUM
Adobe Acrobat and Reader DC < 21.007.20099 and Acrobat and Reader < 17.011.30204 - Use-After-Free
CVSS 5.5
Details
Vulnerabilities 13,962
Exploit Likelihood High