CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,989 vulnerabilities with CWE-119
CVE-2018-11279 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via Buffer Overflow
CVSS 8.8
CVE-2018-15998 HIGH
Adobe Acrobat and Reader DC < 15.006.30457, 15.008.20082-19.008.20081 - Remote Code Execution via Memory Corruption
CVSS 7.8
CVE-2018-15987 HIGH
Adobe Acrobat and Reader DC < 15.006.30457, 15.008.20082-19.008.20081 - Memory Corruption
CVSS 7.8
CVE-2018-4404 HIGH
Safari Proxy Object Type Confusion
CVSS 8.8
CVE-2018-4330 HIGH
iPhone OS < 11.4 - Memory Corruption
CVSS 7.8
CVE-2018-4281 CRITICAL
SwiftNIO < 1.8.0 - Buffer Overflow
CVSS 9.8
CVE-2018-4262 HIGH
Safari < 11.1.2 - Memory Corruption
CVSS 8.8
CVE-2018-4258 CRITICAL
macOS High Sierra < 10.13.5 - Buffer Overflow
CVSS 9.8
CVE-2018-4257 CRITICAL
macOS High Sierra < 10.13.5 - Buffer Overflow
CVSS 9.8
CVE-2018-4189 CRITICAL
Apple tvOS < 11.2.5 - Memory Corruption
CVSS 9.8
CVE-2018-4147 CRITICAL
Safari < 11.0.3 - Memory Corruption
CVSS 9.8
CVE-2018-0678 MEDIUM
BN-SDWBP3 Firmware < 1.0.9 - Buffer Overflow
CVSS 6.8
CVE-2018-0668 CRITICAL
INplc-RT < 3.08 - Buffer Overflow
CVSS 9.8
CVE-2018-0651 CRITICAL
YOKOGAWA iDefine for ProSafe-RS < R1.16.3 - Buffer Overflow in License Management Function
CVSS 9.8
CVE-2018-0641 HIGH
Aterm HC100RC Firmware < 1.0.1 - Authenticated Buffer Overflow via tools_system.cgi Parameters
CVSS 7.2
CVE-2018-0640 HIGH
Aterm HC100RC Firmware < 1.0.1 - Authenticated Buffer Overflow via netWizard.cgi Parameters
CVSS 7.2
CVE-2018-0633 HIGH
Aterm W300P Firmware <= 1.0.13 - Authenticated Buffer Overflow via submit-url Parameter
CVSS 7.2
CVE-2018-0632 HIGH
Aterm W300P Firmware < 1.0.13 - Authenticated Buffer Overflow via HTTP Request
CVSS 7.2
CVE-2018-17470 HIGH
Google Chrome <70.0.3538.67 - Buffer Overflow
CVSS 7.4
CVE-2018-4012 CRITICAL
Webroot BrightCloud SDK - Buffer Overflow in HTTP Header Parsing
CVSS 9.0
CVE-2018-19862 CRITICAL
minishare < 1.4.1 - Remote Code Execution via Long HTTP POST Request
CVSS 9.8
CVE-2018-19861 CRITICAL
minishare < 1.4.1 - Remote Code Execution via Long HTTP HEAD Request
CVSS 9.8
CVE-2018-19523 MEDIUM
DriverAgent 2.2015.7.14 - Buffer Overflow
CVSS 5.5
CVE-2018-17161 CRITICAL
FreeBSD < 11.2-RELEASE-p7, 12.0-RELEASE-p1 - Stack Buffer Overflow in bootpd
CVSS 9.8
CVE-2018-6337 HIGH
Facebook Folly 2017.12.11.00-2018.08.09.00 and HHVM 3.26-3.26.3 - Weak Randomness via Forked Process Buffer Reuse
CVSS 7.5
Details
Vulnerabilities 13,989
Exploit Likelihood High