CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2020-0033 HIGH
Android - Use-After-Free in CryptoPlugin::decrypt
CVSS 7.8
CVE-2020-5254 LOW
NetHack 3.6.1-3.6.6 - Memory Corruption via hilite_status Option
CVSS 3.9
CVE-2020-3846 HIGH
iCloud < 7.17 - Buffer Overflow via Malicious XML Processing
CVSS 8.8
CVE-2020-3840 HIGH
iPadOS < 13.3.1 - Memory Corruption via Racoon Configuration File
CVSS 7.8
CVE-2020-1814 MEDIUM
Huawei NIP6800 <V500R005C00 - Privilege Escalation
CVSS 5.3
CVE-2020-3754 CRITICAL
Adobe Acrobat and Reader <2019.021.20061 - Buffer Overflow
CVSS 9.8
CVE-2020-3752 CRITICAL
Adobe Acrobat <2019.021.20061 - Buffer Overflow
CVSS 9.8
CVE-2020-0020 MEDIUM
Android 10 - Local Information Disclosure via ExifInterface Bounds Check
CVSS 5.5
CVE-2019-8720 HIGH KEV
webkitgtk < 2.26.0 - Remote Code Execution via Malicious Web Content
CVSS 8.8
CVE-2019-25078 MEDIUM
pacparser < 1.4.0 - Buffer Overflow in pacparser_find_proxy
CVSS 5.3
CVE-2019-25063 MEDIUM
Sricam IP CCTV Camera - Memory Corruption
CVSS 5.3
CVE-2019-17006 CRITICAL
Siemens Ruggedcom ROX MX5000 Firmware < 2.14.0 - Buffer Overflow via Missing Length Checks
CVSS 9.8
CVE-2019-15992 HIGH
Cisco ASA <9.6.4.36 & 9.7-9.8.4.15 Authenticated RCE via Lua Script
CVSS 7.2
CVE-2019-15287 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-15285 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-15283 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-14130 HIGH
Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon ...
CVSS 7.8
CVE-2019-14100 HIGH
Snapdragon Auto/Mobile/Compute/IOT - Info Disclosure
CVSS 7.8
CVE-2019-19417 HIGH
Huawei AR160 Firmware - Denial of Service via SIP Module Buffer Overflow
CVSS 7.5
CVE-2019-19416 HIGH
Huawei AR120-S, AR1200, AR1200-S, AR150, AR150-S Firmware - Denial of Service via SIP Module Buffer Overflow
CVSS 7.5
CVE-2019-19415 HIGH
Huawei AR120-S, AR1200, AR1200-S, AR150, AR150-S Firmware - Denial of Service via SIP Message Buffer Overflow
CVSS 7.5
CVE-2019-10626 MEDIUM
Qualcomm Snapdragon Firmware - Memory Corruption via Unvalidated Payload Size
CVSS 5.5
CVE-2019-17562 CRITICAL
Apache CloudStack < 4.13.1.0 - Buffer Overflow via Baremetal Virtual Router MAC Parameter
CVSS 9.8
CVE-2019-15880 CRITICAL
FreeBSD <12.1-STABLE-r356911, <12.1-RELEASE-p5 - Memory Corruption
CVSS 9.8
CVE-2019-5614 CRITICAL
FreeBSD Memory Corruption via IPFW Packet Validation
CVSS 9.8
Details
Vulnerabilities 13,986
Exploit Likelihood High