CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2019-16707 MEDIUM
Hunspell 1.7.0 - Invalid Read in SuggestMgr::leftcommonsubstring
CVSS 6.5
CVE-2019-1214 HIGH KEV
Windows Common Log File System Driver - Elevation of Privilege via Improper Memory Object Handling
CVSS 7.8
CVE-2019-11467 HIGH
Couchbase Server <5.1.2-5.5.0 - Buffer Overflow
CVSS 7.5
CVE-2019-11926 CRITICAL
GD <4.30.9 - Memory Corruption
CVSS 9.8
CVE-2019-11925 CRITICAL
Facebook Hhvm < 3.30.9 - Memory Corruption
CVSS 9.8
CVE-2019-16058 HIGH
OpenSC pam_p11 0.2.0 and 0.3.0 - Buffer Overflow via Long Smart Card Signature
CVSS 7.5
CVE-2019-15946 MEDIUM
OpenSC <0.20.0-rc1 - Buffer Overflow
CVSS 6.4
CVE-2019-15945 MEDIUM
OpenSC <0.20.0-rc1 - Buffer Overflow
CVSS 6.4
CVE-2019-12223 HIGH
Hanwah Techwin SRN-472s <1.07_190502 - Buffer Overflow
CVSS 7.5
CVE-2019-13522 HIGH
ezautomation EZ PLC Editor < 1.8.41 - Remote Code Execution via Crafted Project File
CVSS 7.8
CVE-2019-13518 HIGH
ezautomation EZ Touch Editor < 2.1.0 - Buffer Overflow via Crafted Project File
CVSS 7.8
CVE-2019-15786 CRITICAL
ROBOTIS Dynamixel SDK <= 3.7.11 - Buffer Overflow via Large rxpacket
CVSS 9.8
CVE-2019-15785 CRITICAL
FontForge 20190813-20190820 - Buffer Overflow in PrefsUI_LoadPrefs
CVSS 9.8
CVE-2019-15783 CRITICAL
lute-tab < 2019-08-23 - Buffer Overflow in pdf_print.cc
CVSS 9.8
CVE-2019-9933 CRITICAL
Lexmark CS31X Firmware < lw71.vyl.p230 - Buffer Overflow
CVSS 9.8
CVE-2019-9932 CRITICAL
Lexmark CS31X Firmware < lw71.vyl.p230 - Buffer Overflow
CVSS 9.8
CVE-2019-13484 CRITICAL
Xymon < 4.3.28 - Buffer Overflow in Status-Log Viewer CGI
CVSS 9.8
CVE-2019-13452 CRITICAL
Xymon < 4.3.28 - Buffer Overflow in reportlog.c
CVSS 9.8
CVE-2019-13451 CRITICAL
Xymon < 4.3.28 - Buffer Overflow in history.c
CVSS 9.8
CVE-2019-15548 CRITICAL
ncurses < 5.99.0 - Buffer Overflow via instr and mvwinstr Functions
CVSS 9.8
CVE-2019-14307 HIGH
Ricoh SP C250SF/C252SF/C250DN/C252DN Firmware - Buffer Overflow via SNMP HTTP Parameter Parsing
CVSS 8.8
CVE-2019-14305 HIGH
Ricoh SP C250SF/C252SF/C250DN/C252DN Firmware - Buffer Overflow via HTTP Parameter Parsing
CVSS 8.8
CVE-2019-14300 CRITICAL
Ricoh SP C250SF/C252SF Firmware < 1.13 and SP C250DN/C252DN Firmware < 1.07 - Buffer Overflow via HTTP Cookie Header
CVSS 9.8
CVE-2019-14308 CRITICAL
Ricoh SP C250SF/C252SF/C250DN/C252DN Firmware - Buffer Overflow via LPD Packet Parsing
CVSS 9.8
CVE-2019-1871 HIGH
Cisco IMC Supervisor 3.0.0.0-3.0(4k) - Authenticated DoS & RCE via Import Utility
CVSS 7.2
Details
Vulnerabilities 13,986
Exploit Likelihood High