CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,972 vulnerabilities with CWE-119
CVE-2020-14360 HIGH
X.Org Server < 1.20.10 - Out-of-Bounds Access in XkbSetMap
CVSS 7.8
CVE-2020-9140 CRITICAL
Huawei EMUI and Magic UI - Remote Code Execution via Buffer Overflow
CVSS 9.8
CVE-2020-13573 HIGH
Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3 - Denial of Service via Ethernet/IP Server
CVSS 7.5
CVE-2020-35878 CRITICAL
ozone < 0.1.0 - Use-After-Free via Uninitialized Memory Drop
CVSS 9.8
CVE-2020-35877 CRITICAL
ozone < 0.1.0 - Memory Corruption via Out-of-Bounds Access
CVSS 9.8
CVE-2020-8935 MEDIUM
Asylo < 0.6.0 - Arbitrary Memory Overwrite via Ecall_restore Function
CVSS 5.3
CVE-2020-13520 HIGH
Pixar OpenUSD 20.05 - Memory Corruption
CVSS 7.8
CVE-2020-28220 MEDIUM
Modicon M258 Firmware < 5.0.4.11 and SoMachine/SoMachine Motion - Buffer Overflow via File Transfer
CVSS 6.8
CVE-2020-13524 MEDIUM
Pixar OpenUSD <20.05 - Memory Corruption
CVSS 5.5
CVE-2020-13497 MEDIUM
Pixar OpenUSD 20.05 - Memory Corruption
CVSS 5.5
CVE-2020-13496 MEDIUM
Pixar OpenUSD 20.05 - Memory Corruption
CVSS 6.5
CVE-2020-26243 HIGH
Nanopb <0.4.4 & <0.3.9.7 - Memory Corruption
CVSS 7.5
CVE-2020-7554 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
CVSS 7.8
CVE-2020-7550 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
CVSS 7.8
CVE-2020-3470 CRITICAL
Cisco Enterprise NFV Infrastructure Software < 4.4.1 & IMC 4.0(1a)-4.0(4l) - RCE via API Buffer Overflow
CVSS 9.8
CVE-2020-11196 CRITICAL
Qualcomm APQ8009 and related firmwares - Buffer Overflow via ASF Clip Codec Entry Playback
CVSS 9.8
CVE-2020-5388 MEDIUM
Dell Inspiron 15 7579 2-in-1 BIOS < 1.31.0 - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 6.9
CVE-2020-3604 HIGH
Cisco Webex Meetings < 40.6.11 - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2020-3603 HIGH
Cisco Webex Player for Windows - RCE
CVSS 7.8
CVE-2020-3573 HIGH
Cisco Webex Meetings - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2020-10292 HIGH
Visual Components Network License Server - Denial of Service via Arbitrary Pointer Dereference
CVSS 8.2
CVE-2020-3693 HIGH
Snapdragon Auto Snapdragon Compute Snapdragon Consumer IOT Snapdrag...
CVSS 7.8
CVE-2020-15266 LOW
Tensorflow <2.4.0 - Memory Corruption
CVSS 3.7
CVE-2020-3562 HIGH
Cisco Firepower Threat Defense - Denial of Service via Malformed SSL/TLS Message
CVSS 8.6
CVE-2020-17003 HIGH
Microsoft 3D Viewer Base3D - Memory Handling Code Execution
CVSS 7.8
Details
Vulnerabilities 13,972
Exploit Likelihood High