CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,982 vulnerabilities with CWE-119
CVE-2020-14096 CRITICAL
Xiaomi AI Speaker Firmware < 1.59.6 - Memory Overflow during OTA Firmware Verification
CVSS 9.8
CVE-2020-15173 HIGH
accel-ppp < 1.12.0-92-g38b6104 - Buffer Overflow via L2TP Control Packet AVP
CVSS 8.2
CVE-2020-24074 CRITICAL
silk-v3-decoder <20160922 - Buffer Overflow
CVSS 9.8
CVE-2020-6352 MEDIUM
SAP 3D Visual Enterprise Viewer <9 - DoS
CVSS 4.3
CVE-2020-6351 MEDIUM
SAP 3D Visual Enterprise Viewer <9 - DoS
CVSS 4.3
CVE-2020-6328 MEDIUM
SAP 3D Visual Enterprise Viewer <9 - DoS
CVSS 4.3
CVE-2020-3669 CRITICAL
Snapdragon Auto et al - Buffer Overflow
CVSS 9.8
CVE-2020-3545 MEDIUM
Cisco FXOS < 2.3.1.58 - Authenticated Buffer Overflow via Crafted File Processing
CVSS 6.0
CVE-2020-3453 MEDIUM
Cisco Small Business RV340 - Command Injection
CVSS 4.7
CVE-2020-3451 MEDIUM
Cisco Small Business RV340 - Command Injection
CVSS 4.7
CVE-2020-5778 HIGH
Trading Technologies Messaging <7.1.28.3 - DoS
CVSS 7.5
CVE-2020-25016 CRITICAL
rgb-rust < 0.8.20 - Memory Safety Violation via Struct Byte Manipulation
CVSS 9.1
CVE-2020-5383 MEDIUM
Dell EMC Isilon OneFS 8.2.2 and PowerScale OneFS 9.0.0 - Unauthenticated Buffer Overflow in Likewise Component
CVSS 5.3
CVE-2020-15158 HIGH
libIEC61850 <1.4.3 - Buffer Overflow
CVSS 7.7
CVE-2020-17397 HIGH
Parallels Desktop 15.1.4 - Privilege Escalation
CVSS 8.2
CVE-2020-23574 MEDIUM
Sysax Multi Server 6.90 - Buffer Overflow
CVSS 6.5
CVE-2020-1574 MEDIUM
Microsoft Windows 10 - Remote Code Execution via Crafted Image File
CVSS 5.5
CVE-2020-3500 MEDIUM
Cisco StarOS < 21.18.3 - Unauthenticated Denial of Service via IPv6 Packet Processing
CVSS 6.8
CVE-2020-8230 MEDIUM
NextCloud Desktop Client <2.6.4 - Memory Corruption
CVSS 5.5
CVE-2020-24342 HIGH
Lua <= 5.4.0 - Stack-Based Buffer Overflow via luaO_pushvfstring
CVSS 7.8
CVE-2020-8904 MEDIUM
Asylo < 0.6.0 - Arbitrary Memory Overwrite via ecall_restore Output Length Validation
CVSS 6.4
CVE-2020-15065 MEDIUM
DIGITUS DA-70254 2.073.000.E0008 - Denial of Service via Long Input Values
CVSS 6.5
CVE-2020-15061 MEDIUM
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 - Denial of Service via Long Input Values
CVSS 6.5
CVE-2020-15057 MEDIUM
TP-Link USB Network Server TL-PS310U <2.079.000.t0210 - DoS
CVSS 6.5
CVE-2020-12441 CRITICAL
Ivanti Service Manager HEAT Remote Control 7.4 - DoS
CVSS 9.8
Details
Vulnerabilities 13,982
Exploit Likelihood High