CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

14,073 vulnerabilities with CWE-119
CVE-2026-16412 CRITICAL
Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
CVSS 9.8
CVE-2026-16411 CRITICAL
Memory safety bugs fixed in Firefox 153
CVSS 9.8
CVE-2026-16393 CRITICAL
Incorrect boundary conditions in the Graphics: WebGPU component
CVSS 9.1
CVE-2026-16368 CRITICAL
Incorrect boundary conditions in the JavaScript: WebAssembly component
CVSS 9.8
CVE-2026-16367 CRITICAL
Sandbox escape due to invalid pointer in the Disability Access APIs component
CVSS 10.0
CVE-2026-16364 CRITICAL
Incorrect boundary conditions in the Audio/Video: Playback component
CVSS 9.1
CVE-2026-16361 CRITICAL
Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13
CVSS 9.8
CVE-2026-16360 CRITICAL
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
CVSS 9.8
CVE-2026-16359 CRITICAL
Incorrect boundary conditions in the Audio/Video: GMP component
CVSS 9.1
CVE-2026-16357 CRITICAL
Mozilla Firefox - Incorrect Boundary Conditions in the Graphics Component
CVSS 9.8
CVE-2026-16350 CRITICAL
Incorrect boundary conditions in the Audio/Video: cubeb component
CVSS 9.8
CVE-2026-16248 HIGH
Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
CVSS 8.8
CVE-2026-16225 MEDIUM
davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write
CVSS 6.3
CVE-2026-16097 HIGH
Shibby Tomato Scheduler Name sub_42537C stack-based overflow
CVSS 8.8
CVE-2026-16096 HIGH
Shibby Tomato webmon_recent_domains sub_40BB50 stack-based overflow
CVSS 8.8
CVE-2026-16095 HIGH
Shibby Tomato rc setup_conntrack out-of-bounds write
CVSS 8.8
CVE-2026-16013 MEDIUM
liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
CVSS 5.3
CVE-2026-55398 LOW
Absolute Secure Access < 14.55 Tunnel Protocol - Server Denial of Service
CVSS 3.7
CVE-2026-33444 LOW
Absolute Secure Access < 14.55 Server - Non-Persistent Denial of Service
CVSS 3.7
CVE-2026-20156 HIGH
Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities
CVSS 8.1
CVE-2026-15701 CRITICAL
Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow
CVSS 9.8
CVE-2026-15696 HIGH
Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow
CVSS 8.8
CVE-2026-15695 HIGH
Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow
CVSS 8.8
CVE-2026-15694 HIGH
Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow
CVSS 8.8
CVE-2026-15693 HIGH
Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow
CVSS 8.8
Details
Vulnerabilities 14,073
Exploit Likelihood High