CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,964 vulnerabilities with CWE-119
CVE-2021-45067 MEDIUM
Adobe Acrobat and Reader DC < 21.007.20099 & < 17.011.30204 - Memory Access After Buffer End
CVSS 5.5
CVE-2021-44712 MEDIUM
Adobe Acrobat and Reader DC < 21.007.20099 and Acrobat and Reader < 17.011.30204 - Use-After-Free
CVSS 5.5
CVE-2021-39633 MEDIUM
Android - Local Information Disclosure via Invalid Memory Access in gre_handle_offloads
CVSS 5.5
CVE-2021-45762 MEDIUM
GPAC 1.1.0 - Denial of Service via gf_sg_vrml_mf_reset()
CVSS 5.5
CVE-2021-45760 MEDIUM
GPAC 1.1.0 - Denial of Service via gf_list_last() Invalid Memory Address Dereference
CVSS 5.5
CVE-2021-34934 HIGH
Bentley View < 10.16.02 - Remote Code Execution via JT File Parsing
CVSS 7.8
CVE-2021-34874 HIGH
Bentley View < 10.16.02 - Remote Code Execution via 3DS File Processing
CVSS 7.8
CVE-2021-46053 MEDIUM
Binaryen 103 - Denial of Service
CVSS 5.5
CVE-2021-40027 HIGH
HarmonyOS < 2.0 - NULL Pointer Dereference in Bone Voice ID TA
CVSS 7.5
CVE-2021-30289 HIGH
Snapdragon Auto- Snapdragon Compute - Buffer Overflow
CVSS 7.8
CVE-2021-45709 CRITICAL
crypto2 <2021-10-08 - Memory Corruption
CVSS 9.8
CVE-2021-40393 CRITICAL
Gerbv <2.7.0 - Code Injection
CVSS 9.8
CVE-2021-44920 MEDIUM
gpac 1.1.0 - Invalid Memory Address Dereference in dump_od_to_saf.isra
CVSS 5.5
CVE-2021-45293 MEDIUM
Binaryen 103 - Denial of Service via Invalid Memory Address Dereference in wasm::WasmBinaryBuilder::visitLet
CVSS 5.5
CVE-2021-40784 HIGH
Adobe Premiere Rush <1.5.16 - Memory Corruption
CVSS 7.8
CVE-2021-40783 HIGH
Adobe Premiere Rush <1.5.16 - Memory Corruption
CVSS 7.8
CVE-2021-43083 HIGH
Apache PLC4X - PLC4C <0.9.1 - Buffer Overflow
CVSS 8.8
CVE-2021-4011 HIGH
xorg-x11-server <21.1.2, <1.20.14 - Memory Corruption
CVSS 7.8
CVE-2021-4010 HIGH
xorg-x11-server <21.1.2, <1.20.14 - Memory Corruption
CVSS 7.8
CVE-2021-4009 HIGH
xorg-x11-server <21.1.2, 1.20.14 - Memory Corruption
CVSS 7.8
CVE-2021-4008 HIGH
xorg-x11-server <21.1.2, <1.20.14 - Memory Corruption
CVSS 7.8
CVE-2021-44538 CRITICAL
Matrix libolm < 3.2.7 - Buffer Overflow in olm_session_describe
CVSS 9.8
CVE-2021-44440 HIGH
Siemens JT Open Toolkit < 11.1.1.0 and JT Utilities < 13.1.1.0 - Memory Corruption via Crafted JT File Parsing
CVSS 7.8
CVE-2021-21951 CRITICAL
Anker Eufy Homebase 2 2.1.6.9h - Remote Code Execution via CMD_DEVICE_GET_SERVER_LIST_REQUEST
CVSS 10.0
CVE-2021-21950 CRITICAL
Anker Eufy Homebase 2 Firmware 2.1.6.9h - Remote Code Execution via CMD_DEVICE_GET_SERVER_LIST_REQUEST
CVSS 10.0
Details
Vulnerabilities 13,964
Exploit Likelihood High