CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2019-2248 HIGH
Qualcomm Snapdragon - Buffer Overflow
CVSS 7.8
CVE-2019-12044 HIGH
Citrix NetScaler Gateway/ADC Buffer Overflow in 10.5.x-10.5.70.x, 11.1.x-11.1.59.10, 12.0.x-12.0.59.8, 12.1.x-12.1.49.23
CVSS 7.5
CVE-2019-0170 MEDIUM
Intel Converged Security Management Engine Firmware < 12.0.35 - Buffer Overflow via Local Access
CVSS 6.7
CVE-2019-0153 CRITICAL
Intel Converged Security Management Engine Firmware < 12.0.35 - Unauthenticated Buffer Overflow via Network Access
CVSS 9.8
CVE-2019-0119 MEDIUM
Intel Xeon D Family Firmware - Buffer Overflow
CVSS 6.7
CVE-2019-0113 MEDIUM
Intel Graphics Driver - Denial of Service via Insufficient Bounds Checking
CVSS 5.5
CVE-2019-1768 MEDIUM
Cisco NX-OS < 8.3(1) - Authenticated Command Injection via CLI Command Argument
CVSS 6.7
CVE-2019-1773 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1772 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1771 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1767 MEDIUM
Cisco NX-OS < 8.3(1) - Authenticated Command Injection via CLI Argument
CVSS 6.7
CVE-2019-11059 CRITICAL
Das U-Boot 2016.11-rc1-2019.04 - Buffer Overflow in ext4 64-bit Extension Handling
CVSS 9.8
CVE-2019-7181 HIGH
myQNAPcloud Connect <1.3.3.0925 - Buffer Overflow
CVSS 7.5
CVE-2019-3561 CRITICAL
HHVM < 3.27.7 - Out-of-Bounds Memory Access in strrpos and strripos Functions
CVSS 9.8
CVE-2019-11577 CRITICAL
dhcpcd < 7.2.1 - Buffer Overflow in dhcp6_findna
CVSS 9.8
CVE-2019-9810 HIGH
Firefox < 66.0.1 and ESR < 60.6.1 - Memory Corruption via IonMonkey JIT Compiler
CVSS 8.8
CVE-2019-9793 MEDIUM
Firefox < 66.0, Firefox ESR < 60.6, Thunderbird < 60.6 - Memory Corruption via Disabled Spectre Mitigations
CVSS 5.9
CVE-2019-11493 HIGH
VeryPDF 4.1 - Memory Overflow in pdfocx!CxImageTIF::operator
CVSS 7.8
CVE-2019-11418 CRITICAL
TRENDnet TEW-632BRP <1.010B32 - Buffer Overflow
CVSS 9.8
CVE-2019-10245 HIGH
Eclipse OpenJ9 < 0.14.0 - Denial of Service via Bytecode Verifier Bypass
CVSS 7.5
CVE-2019-10655 CRITICAL
Grandstream GAC2500/GXP2200/GVC3202/GXV3275/GXV3240 < 1.0.3.219 - Unauthenticated RCE via getlogcat
CVSS 9.8
CVE-2019-7524 HIGH
Dovecot <2.2.36.3, 2.3.x <2.3.5.1 - Buffer Overflow
CVSS 8.8
CVE-2019-10060 HIGH
Verix Multi-app Conductor <2.7 - Buffer Overflow
CVSS 8.1
CVE-2019-9969 HIGH
XnView Classic 2.48 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9968 HIGH
XnView Classic 2.48 - Denial of Service via Crafted File
CVSS 7.8
Details
Vulnerabilities 13,986
Exploit Likelihood High