CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2019-14113 CRITICAL
Snapdragon Auto Snapdragon Compute Snapdragon Connectivity Snapdrag...
CVSS 9.8
CVE-2019-14009 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via TZ Command Handler
CVSS 7.8
CVE-2019-10624 HIGH
Qualcomm APQ8096AU Firmware - Buffer Overflow via Integer Truncation in Vendor Command Handling
CVSS 7.8
CVE-2019-5105 HIGH
CODESYS <V3.5.16.10 - Memory Corruption
CVSS 7.5
CVE-2019-17135 HIGH
Foxit PhantomPDF 9.5.0.20723 - Remote Code Execution via DXF File Parsing
CVSS 7.8
CVE-2019-20396 MEDIUM
libyang - Denial of Service via Malformed Pattern Statement in lys_parse_path
CVSS 6.5
CVE-2019-20392 MEDIUM
libyang < 1.0-r1 - Denial of Service via Invalid Memory Access in resolve_feature_value()
CVSS 6.5
CVE-2019-20391 MEDIUM
libyang < 1.0-r3 - Denial of Service via if-feature Statement in Bit
CVSS 6.5
CVE-2019-14006 CRITICAL
Snapdragon Auto et al - Buffer Overflow
CVSS 9.8
CVE-2019-14004 CRITICAL
Snapdragon Auto et al - Buffer Overflow
CVSS 9.8
CVE-2019-20172 HIGH
SerenityOS < 2019-12-30 - Privilege Escalation via Kernel Stack Return Address Overwrite
CVSS 7.8
CVE-2019-20053 MEDIUM
UPX 3.95 - Invalid Memory Address Dereference in canUnpack Function
CVSS 5.5
CVE-2019-18236 HIGH
we-con PLC Editor 1.3.5_20190129 - Buffer Overflow via Crafted Project File
CVSS 7.8
CVE-2019-16463 CRITICAL
Adobe Acrobat and Reader <2019.021.20056 - RCE
CVSS 9.8
CVE-2019-16460 CRITICAL
Adobe Acrobat and Reader <2019.021.20056 - RCE
CVSS 9.8
CVE-2019-16455 CRITICAL
Adobe Acrobat and Reader <2019.021.20056 - RCE
CVSS 9.8
CVE-2019-16446 CRITICAL
Adobe Acrobat Reader <2019.021.20056 - RCE
CVSS 9.8
CVE-2019-8745 HIGH
iCloud < 7.14 - Buffer Overflow via Maliciously Crafted Text File
CVSS 8.8
CVE-2019-8598 MEDIUM
iCloud < 7.12 - Memory Read via Input Validation Issue
CVSS 5.5
CVE-2019-8577 HIGH
Apple iCloud < 7.12 - Memory Corruption via Improper Input Validation
CVSS 7.8
CVE-2019-8555 HIGH
macOS < 10.14.4 - Remote Code Execution via Buffer Overflow
CVSS 7.8
CVE-2019-11400 CRITICAL
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 - Buffer Overflow via ccp_act Parameter
CVSS 9.8
CVE-2019-10544 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via Diag Handler Buffer Length Check
CVSS 7.8
CVE-2019-14608 HIGH
Intel NUC Firmware - Authenticated Privilege Escalation via Improper Buffer Restrictions
CVSS 7.8
CVE-2019-13942 HIGH
Siemens EN100 Ethernet Module - Denial of Service via Webserver Buffer Overflow
CVSS 7.5
Details
Vulnerabilities 13,986
Exploit Likelihood High