CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,989 vulnerabilities with CWE-119
CVE-2018-11961 HIGH
Android - Memory Corruption in GNSS Configuration Update
CVSS 7.8
CVE-2018-5200 HIGH
KMPlayer <4.2.2.15 - Buffer Overflow
CVSS 7.8
CVE-2018-1771 HIGH
IBM Domino 9.0-9.0.1 - Buffer Overflow via nsd.exe Command Line Argument Parsing
CVSS 8.4
CVE-2018-20304 MEDIUM
libexcel 0.01 - Denial of Service via Long Second Argument in wbook_addworksheet
CVSS 6.5
CVE-2018-20299 CRITICAL
Bosch Smart Home <6.52.4 - Buffer Overflow
CVSS 9.8
CVE-2018-20213 HIGH
libexcel 0.01 - Denial of Service via Long Worksheet Name
CVSS 7.5
CVE-2018-19036 CRITICAL
Bosch Common Product Platform 4/6/7/7.3 Firmware >=6.32 - Remote Code Execution
CVSS 9.8
CVE-2018-14856 MEDIUM
Samsung Galaxy S6 Firmware - Buffer Overflow in dhd_bus_flow_ring_create_response
CVSS 6.3
CVE-2018-14855 MEDIUM
Samsung Galaxy S6 Firmware - Buffer Overflow in dhd_bus_flow_ring_flush_response
CVSS 6.3
CVE-2018-14854 MEDIUM
Samsung Galaxy S6 Firmware - Buffer Overflow in dhd_bus_flow_ring_delete_response
CVSS 6.3
CVE-2018-14852 MEDIUM
Samsung Galaxy S6 Firmware - Out-of-Bounds Memory Access in bcmdhd4358 Wi-Fi Driver
CVSS 6.3
CVE-2018-18096 MEDIUM
Intel QuickAssist Technology for Linux - Authenticated Denial of Service via Improper Memory Handling
CVSS 5.5
CVE-2018-12206 MEDIUM
Intel QuickAssist Technology for Linux - Authenticated Denial of Service via Hardware Access Misconfiguration
CVSS 5.5
CVE-2018-11463 HIGH
SINUMERIK 808D V4.7/V4.8, 828D < V4.7 SP6 HF1, 840D sl < V4.7 SP6 HF5/< V4.8 SP3 - Authenticated Buffer Overflow
CVSS 7.8
CVE-2018-20097 MEDIUM
Exiv2 0.27-RC3 - Denial of Service via Crafted TIFF Input
CVSS 6.5
CVE-2018-18314 CRITICAL
perl < 5.26.3 - Buffer Overflow via Crafted Regular Expression
CVSS 9.8
CVE-2018-11905 CRITICAL
Android - Buffer Overflow in WLAN Function via Firmware Input
CVSS 9.8
CVE-2018-19891 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-19890 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-19889 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-19888 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-19887 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-19886 MEDIUM
Freeware Advanced Audio Coder <1.29.9.2 - Memory Corruption
CVSS 5.5
CVE-2018-18312 CRITICAL
Perl < 5.26.3 and 5.28.0 < 5.28.1 - Buffer Overflow via Crafted Regular Expression
CVSS 9.8
CVE-2018-19864 CRITICAL
NUUO NVRmini2 Firmware <= 3.9.1 - Remote Code Execution via Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 13,989
Exploit Likelihood High