CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2019-9967 HIGH
XnView Classic 2.48 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9966 HIGH
XnView Classic 2.48 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9965 HIGH
XnView MP 0.93.1 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9964 HIGH
XnView MP 0.93.1 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9963 HIGH
XnView MP 0.93.1 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9962 HIGH
XnView MP 0.93.1 - Denial of Service via Crafted File
CVSS 7.8
CVE-2019-9895 CRITICAL
PuTTY < 0.71 - Buffer Overflow via Server-to-Client Forwarding
CVSS 9.8
CVE-2019-1616 HIGH
Cisco NX-OS 8.2-8.3(1) - Unauthenticated Denial of Service via Cisco Fabric Services Packet Buffer Overflow
CVSS 8.6
CVE-2019-9675 HIGH
PHP <7.1.27, <7.3.3 - Buffer Overflow
CVSS 8.1
CVE-2019-1605 HIGH
Cisco NX-OS - Authenticated Remote Code Execution via NX-API HTTP/HTTPS Request
CVSS 7.8
CVE-2019-3712 HIGH
Dell WES Wyse Device Agent < 14.1.2.9 & ThinLinux HAgent < 5.4.55_00.10 - Unauthenticated Buffer Overflow
CVSS 8.2
CVE-2019-9588 HIGH
Xpdf <4.01 - Memory Corruption
CVSS 7.8
CVE-2019-0613 HIGH
.NET Framework and Visual Studio - Remote Code Execution via Unchecked Source Markup
CVSS 8.8
CVE-2019-6224 HIGH
iPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2, watchOS < 5.1.3 - Remote Code Execution via FaceTime Call
CVSS 8.8
CVE-2019-6213 HIGH
iPhone OS < 12.1.3 - Remote Code Execution via Buffer Overflow
CVSS 7.8
CVE-2019-1663 CRITICAL
Cisco RV110W RV130W RV215W - Unauthenticated Remote Code Execution via Web Management Interface
CVSS 9.8
CVE-2019-3598 MEDIUM
McAfee Agent 5.0.0-5.0.5 - Unauthenticated Denial of Service via Crafted UDP Packets
CVSS 5.3
CVE-2019-5670 HIGH
NVIDIA Windows GPU Display Driver - Memory Corruption in DxgkDdiEscape Handler
CVSS 7.8
CVE-2019-5669 HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via DxgkDdiEscape Handler
CVSS 7.8
CVE-2019-8375 CRITICAL
WebKitGTK < 2.23.90 and WebKitGTK+ < 2.22.6 - Buffer Overflow via Script Dialog Size Manipulation
CVSS 9.8
CVE-2019-9019 MEDIUM
British Airways Entertainment System - Buffer Overflow via USB HID Input
CVSS 6.8
CVE-2019-8996 CRITICAL
Signiant Manager+Agents < 13.5 - Buffer Overflow via Set Command
CVSS 9.8
CVE-2019-1684 MEDIUM
Cisco IP Phone 7800/8800 < 12.6(1)MN80 - DoS via Cisco Discovery Protocol or LLDP
CVSS 6.5
CVE-2019-5762 HIGH
Google Chrome < 72.0.3626.81 - Remote Code Execution via PDFium Caching
CVSS 8.8
CVE-2019-3812 MEDIUM
QEMU 2.10.0-3.1.0 - Out-of-Bounds Read in I2C DDC Function
CVSS 4.4
Details
Vulnerabilities 13,986
Exploit Likelihood High