CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,964 vulnerabilities with CWE-119
CVE-2021-43012 HIGH
Adobe Prelude <10.1 - Memory Corruption
CVSS 7.8
CVE-2021-43011 HIGH
Adobe Prelude <10.1 - Memory Corruption
CVSS 7.8
CVE-2021-42725 HIGH
Adobe Bridge < 11.1.2 - Memory Corruption via Malicious M4A File
CVSS 7.8
CVE-2021-43013 HIGH
Adobe Media Encoder <15.4.1 - Memory Corruption
CVSS 7.8
CVE-2021-42726 HIGH
Adobe Media Encoder < 15.4 - Memory Corruption via Malicious M4A File
CVSS 7.8
CVE-2021-26336 MEDIUM
AMD EPYC 7003 Firmware < milanpi-sp3_1.0.0.4 - Denial of Service via SMU Memory Bounds Check Bypass
CVSS 5.5
CVE-2021-41289 MEDIUM
ASUS P453UJ BIOS - Memory Buffer Overflow via Designated Memory DataBuffer
CVSS 6.3
CVE-2021-1973 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption via FTM Diag Command
CVSS 7.8
CVE-2021-31883 HIGH
Capital Embedded AR Classic 431-422 and R20-11 < V2303 - Denial of Service via DHCP ACK Vendor Option Length
CVSS 7.1
CVE-2021-31882 MEDIUM
Capital Embedded AR Classic - Denial of Service via DHCP ACK Packet Processing
CVSS 6.5
CVE-2021-41771 HIGH
GO < 1.16.10 - Memory Corruption
CVSS 7.5
CVE-2021-37002 CRITICAL
Huawei EMUI and Magic UI - Memory Out-of-Bounds Access
CVSS 9.8
CVE-2021-40117 HIGH
Cisco ASA & FTD SSL/TLS Packet Processing DoS
CVSS 8.6
CVE-2021-34783 HIGH
Cisco ASA/Firepower Threat Defense - Unauthenticated DoS via Crafted SSL/TLS Message
CVSS 8.6
CVE-2021-34781 HIGH
Cisco Firepower Threat Defense - Denial of Service via SSH Connection Handling
CVSS 8.6
CVE-2021-34595 HIGH
Wago 750-823 Firmware < fw10 - Out-of-Bounds Access
CVSS 8.1
CVE-2021-34859 HIGH
TeamViewer 15.16.8.0 - Remote Code Execution via TVS File Parsing
CVSS 8.8
CVE-2021-34856 HIGH
Parallels Desktop 16.1.3 - Privilege Escalation via virtio-gpu Memory Corruption
CVSS 8.8
CVE-2021-38473 HIGH
versiondog < 8.0.0 - Stack Overflow via Improper Argument Control
CVSS 8.0
CVE-2021-30316 HIGH
Snapdragon Auto-Snapdragon Mobile - Memory Corruption
CVSS 8.4
CVE-2021-3746 MEDIUM
libtpms <0.8.5-0.7.9-0.6.6 - Memory Corruption
CVSS 6.5
CVE-2021-3889 HIGH
libmobi < 0.8 - Use of Out-of-range Pointer Offset
CVSS 8.1
CVE-2021-3888 HIGH
libmobi < 0.8 - Use of Out-of-range Pointer Offset
CVSS 8.1
CVE-2021-38442 HIGH
FATEK Automation WinProladder <3.30 - Code Injection
CVSS 7.8
CVE-2021-38436 HIGH
FATEK Automation WinProladder <3.30 - Memory Corruption
CVSS 7.8
Details
Vulnerabilities 13,964
Exploit Likelihood High