CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,972 vulnerabilities with CWE-119
CVE-2020-27738 MEDIUM
Nucleus ReadyStart V3 < 2017.02.3 - Denial of Service via DNS Record Decompression
CVSS 6.5
CVE-2020-26997 HIGH
Solid Edge <SE2020MP13, SE2020MP14, SE2021MP4 - RCE
CVSS 7.8
CVE-2020-11305 MEDIUM
Qualcomm APQ8009 Firmware - Integer Overflow in Boot Argument Length Check
CVSS 6.8
CVE-2020-1899 HIGH
HHVM <4.32.3, 4.33.0-4.62.0 - Memory Corruption
CVSS 7.5
CVE-2020-35522 MEDIUM
libtiff - Denial of Service via Crafted TIFF in tif_pixarlog.c
CVSS 5.5
CVE-2020-35521 MEDIUM
libtiff - Denial of Service via Crafted TIFF File
CVSS 5.5
CVE-2020-25690 HIGH
FontForge < 20200314 - Out-of-Bounds Write via SFD LayerCount Token Parsing
CVSS 8.8
CVE-2020-11286 MEDIUM
Qualcomm PM8004 - Untrusted Pointer Dereference via USB Control Transfers
CVSS 6.8
CVE-2020-11194 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Improper Response Buffer Length Check
CVSS 7.8
CVE-2020-12365 MEDIUM
Intel Graphics Drivers < 15.33.51.5146 - Authenticated Denial of Service via Untrusted Pointer Dereference
CVSS 5.5
CVE-2020-12373 MEDIUM
Intel BMC Firmware < 2.47 - Use-After-Free
CVSS 6.7
CVE-2020-12370 MEDIUM
Intel Graphics Drivers < 26.20.100.8141 - Denial of Service via Untrusted Pointer Dereference
CVSS 5.5
CVE-2020-27874 HIGH
Tencent WeChat 7.0.18 - Remote Code Execution via WXAM Decoder Memory Corruption
CVSS 8.8
CVE-2020-13571 HIGH
Accusoft ImageGear 19.8 - Out-of-Bounds Write via SGI RLE Decompression
CVSS 8.8
CVE-2020-13561 HIGH
Accusoft ImageGear 19.8 - Out-of-Bounds Write in TIFF Parser
CVSS 8.8
CVE-2020-17426 HIGH
Foxit Studio Photo 3.6.6.922 - Remote Code Execution via CR2 File Handling
CVSS 7.8
CVE-2020-27006 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0.1 - Memory Corruption via PCT File Parsing
CVSS 7.8
CVE-2020-27003 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0.1 - Remote Code Execution via TIFF File Parsing
CVSS 7.8
CVE-2020-27000 HIGH
JT2Go < V13.1.0.1 - Memory Corruption
CVSS 7.8
CVE-2020-28144 CRITICAL
Moxa EDR-G903/G902/810 Firmware - Remote Code Execution via Memory Buffer Overflow
CVSS 9.8
CVE-2020-29557 CRITICAL KEV
D-Link DIR-825 R1 Firmware < 3.0.1 - Unauthenticated Remote Code Execution via Web Interface Buffer Overflow
CVSS 9.8
CVE-2020-11181 HIGH
Qualcomm PM3003A and related firmware - Memory Corruption via CVP Process Control Command
CVSS 7.8
CVE-2020-11180 HIGH
Qualcomm AQT1000 - Out-of-Bounds Memory Access in Computer Vision Control
CVSS 7.8
CVE-2020-11150 MEDIUM
Qualcomm Aqt1000 - Memory Corruption
CVSS 6.7
CVE-2020-11149 MEDIUM
Qualcomm Snapdragon - Out-of-Bounds Memory Access in Camera Driver
CVSS 6.7
Details
Vulnerabilities 13,972
Exploit Likelihood High