CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,968 vulnerabilities with CWE-119
CVE-2021-1509 HIGH
Cisco vEdge Firmware 20.4 - Remote Code Execution and Denial of Service
CVSS 7.5
CVE-2021-32020 CRITICAL
Amazon FreeRTOS < 10.4.3 - Heap-Based Buffer Overflow
CVSS 9.8
CVE-2021-1402 HIGH
Cisco Firepower Threat Defense 6.3.0-6.3.9 - Unauthenticated Denial of Service via SSL/TLS Message Handling
CVSS 8.6
CVE-2021-0242 MEDIUM
Juniper Junos OS on EX4300 - Denial of Service via DMA Buffer Exhaustion
CVSS 6.5
CVE-2021-0227 HIGH
Juniper Networks Junos OS J-Web - DoS
CVSS 7.5
CVE-2021-3496 HIGH
jhead 3.06 - Heap-Based Buffer Overflow in Get16u Function
CVSS 7.8
CVE-2021-3498 HIGH
GStreamer < 1.18.4 - Heap Corruption via Malformed Matroska File Parsing
CVSS 7.8
CVE-2021-31261 MEDIUM
GPAC 1.0.1 - Memory Read via Crafted MP4Box File
CVSS 5.5
CVE-2021-27692 CRITICAL
Tendacn G1 Firmware - Memory Corruption
CVSS 9.8
CVE-2021-27691 CRITICAL
Tenda G0/G1/G3 <15.11.0.6-17 - Command Injection
CVSS 9.8
CVE-2021-21784 HIGH
Accusoft ImageGear 19.8 - Out-of-Bounds Write via JPG SOF Marker Processing
CVSS 7.8
CVE-2021-28878 HIGH
Rust < 1.52.0 - Memory Safety Violation via Zip Iterator next_back() and next()
CVSS 7.5
CVE-2021-28877 HIGH
Rust < 1.51.0 - Memory Safety Violation via Zip Iterator Implementation
CVSS 7.5
CVE-2021-1480 HIGH
Cisco Catalyst SD-WAN Manager 20.4-20.4.1 and SD-WAN vManage < 19.2.4 - Unauthenticated Remote Code Execution
CVSS 7.8
CVE-2021-1479 HIGH
Cisco SD-WAN vManage < 19.2.4 and Catalyst SD-WAN Manager 20.4 - Remote Code Execution and Privilege Escalation
CVSS 7.8
CVE-2021-1473 MEDIUM
Cisco RV340 RV340W RV345 RV345P Firmware < 1.0.03.21 - Authentication Bypass and Remote Code Execution
CVSS 5.3
CVE-2021-1472 MEDIUM
Cisco RV Series Firmware - Unauthenticated RCE and Auth Bypass
CVSS 5.3
CVE-2021-1459 CRITICAL
Cisco RV110W RV130 RV130W RV215W - Unauthenticated Remote Code Execution via Web Interface
CVSS 9.8
CVE-2021-1309 HIGH
Cisco RV Series Routers - Unauthenticated Remote Code Execution or Denial of Service via LLDP
CVSS 7.4
CVE-2021-1308 HIGH
Cisco RV Series Routers - Unauthenticated Remote Code Execution or Denial of Service via LLDP
CVSS 7.4
CVE-2021-1251 HIGH
Cisco RV Series Routers - Unauthenticated Remote Code Execution or Denial of Service via LLDP
CVSS 7.4
CVE-2021-1137 HIGH
Cisco Catalyst SD-WAN Manager 20.4-20.4.1 and SD-WAN vManage < 19.2.4 - Remote Code Execution and Privilege Escalation
CVSS 7.8
CVE-2021-30454 CRITICAL
outer_cgi <0.2.1 - Memory Corruption
CVSS 9.8
CVE-2021-22991 CRITICAL KEV
BIG-IP <16.0.1.1, <15.1.2.1, <14.1.4, <13.1.3.6, <12.1.5.3 - DoS/RCE
CVSS 9.8
CVE-2021-3470 MEDIUM
Redis < 5.0.10, < 6.0.9, < 6.2.0 - Heap Overflow via Non-Jemalloc/Glibc Allocator
CVSS 5.3
Details
Vulnerabilities 13,968
Exploit Likelihood High