CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,982 vulnerabilities with CWE-119
CVE-2020-3375 CRITICAL
Cisco SD-WAN Solution Software - Buffer Overflow
CVSS 9.8
CVE-2020-8174 HIGH
node <10.21.0, 12.18.0, 14.4.0 - Memory Corruption
CVSS 8.1
CVE-2020-12031 HIGH
FactoryTalk View SE - Authenticated Memory Corruption leading to Arbitrary Code Execution
CVSS 7.5
CVE-2020-3331 CRITICAL
Cisco RV110W and RV215W - Unauthenticated Remote Code Execution via Web Management Interface
CVSS 9.8
CVE-2020-3323 CRITICAL
Cisco Small Business RV110W-215W - RCE
CVSS 9.8
CVE-2020-3146 HIGH
Cisco RV110W-215W - Authenticated RCE
CVSS 8.8
CVE-2020-3145 HIGH
Cisco RV110W-215W - Authenticated RCE
CVSS 8.8
CVE-2020-15350 CRITICAL
RIOT 2020.04 - Buffer Overflow in Base64 Decoder
CVSS 9.8
CVE-2020-15584 MEDIUM
Android - Out-of-Bounds Access via 4K Wallpaper Image Processing
CVSS 5.5
CVE-2020-15582 MEDIUM
Android P(9.0) and Q(10.0) on Exynos 7885 - Buffer Overflow in Bluetooth Low Energy Component
CVSS 5.5
CVE-2020-15564 MEDIUM
Xen < 4.13.1 - Denial of Service via Misaligned VCPUOP_register_vcpu_info Hypercall
CVSS 6.5
CVE-2020-15563 MEDIUM
Xen 4.8.0-4.13.0 - Denial of Service via Dirty Video RAM Tracking
CVSS 6.5
CVE-2020-5968 HIGH
NVIDIA Virtual GPU Manager <8.4-10.3 - Memory Corruption
CVSS 7.8
CVE-2020-9642 HIGH
Adobe Illustrator < 24.1.2 - Buffer Overflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2020-9605 HIGH
Adobe Acrobat and Reader DC - Buffer Overflow leading to Remote Code Execution
CVSS 7.8
CVE-2020-9604 HIGH
Adobe Acrobat and Reader DC < 2020.006.20042 - Memory Corruption
CVSS 7.8
CVE-2020-9598 MEDIUM
Adobe Acrobat and Reader DC < 2020.006.20042 - Information Disclosure via Invalid Memory Access
CVSS 5.5
CVE-2020-9595 MEDIUM
Adobe Acrobat and Reader DC < 2020.006.20042 - Information Disclosure via Invalid Memory Access
CVSS 5.5
CVE-2020-9593 MEDIUM
Adobe Acrobat and Reader DC < 2020.006.20042 - Information Disclosure via Invalid Memory Access
CVSS 5.5
CVE-2020-11520 HIGH
WinMagic SecureDoc < 8.5 - Arbitrary Kernel Memory Write via SDDisk2k.sys IOCTL Dispatcher
CVSS 7.8
CVE-2020-14968 CRITICAL
jsrsasign < 8.0.17 - Signature Validation Bypass via Prepended Null Bytes
CVSS 9.8
CVE-2020-14967 CRITICAL
jsrsasign <8.0.18 - Memory Corruption
CVSS 9.8
CVE-2020-3296 HIGH
Cisco Small Business RV320-0 - Authenticated RCE
CVSS 7.2
CVE-2020-3295 HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3294 HIGH
Cisco Small Business RV320-0 - Authenticated RCE
CVSS 7.2
Details
Vulnerabilities 13,982
Exploit Likelihood High