CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,960 vulnerabilities with CWE-119
CVE-2026-24798 CRITICAL
GaijinEntertainment DagorEngine - Buffer Overflow
CVE-2026-24794 CRITICAL
CardboardPowered <1.21.4 - Buffer Overflow
CVE-2026-1465 HIGH
anyRTC-RTMP-OpenSource <1.0 - Memory Corruption
CVE-2026-1425 MEDIUM
pymumu SmartDNS <47.1 - Buffer Overflow
CVSS 5.6
CVE-2026-1420 HIGH
Tenda AC23 16.03.07.52 - Buffer Overflow via WifiExtraSet wpapsk_crypto Parameter
CVSS 8.8
CVE-2026-1418 MEDIUM
GPAC < 2.4.0 - Out-of-Bounds Write in SRT Subtitle Import
CVSS 5.3
CVE-2026-1260 HIGH
Sentencepiece < 0.2.1 - Memory Corruption via Vulnerable Model File
CVSS 7.8
CVE-2026-1329 HIGH
Tenda AX1803 1.0.0.1 - Stack-Based Buffer Overflow via WifiGuestSet Guest Parameters
CVSS 8.8
CVE-2026-1328 HIGH
Totolink NR1800X 9.1.0u.6279_B20210910 - Buffer Overflow via setWizardCfg POST Parameter
CVSS 8.8
CVE-2026-1162 CRITICAL
UTT HiPER 810 1.7.4-141218 - Buffer Overflow via setSysAdm passwd1 Parameter
CVSS 9.8
CVE-2026-1158 HIGH
Totolink LR350 9.3.5u.6369_B20220309 - Buffer Overflow via setWizardCfg SSID Parameter
CVSS 8.8
CVE-2026-1157 HIGH
Totolink LR350 9.3.5u.6369_B20220309 - Buffer Overflow via setWiFiEasyCfg ssid Parameter
CVSS 8.8
CVE-2026-1156 HIGH
Totolink LR350 9.3.5u.6369_B20220309 - Buffer Overflow via setWiFiBasicCfg SSID Parameter
CVSS 8.8
CVE-2026-1155 HIGH
Totolink LR350 9.3.5u.6369_B20220309 - Buffer Overflow via setWiFiEasyGuestCfg ssid Parameter
CVSS 8.8
CVE-2026-1145 MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor_ta
CVSS 6.3
CVE-2026-1144 MEDIUM
quickjs-ng quickjs < 0.11.0 - Use-After-Free in Atomics Ops Handler
CVSS 6.3
CVE-2026-1143 HIGH
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Buffer Overflow via setWiFiEasyGuestCfg ssid Parameter
CVSS 8.8
CVE-2026-1140 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow in /goform/ConfigExceptAli
CVSS 8.8
CVE-2026-1139 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow in /goform/ConfigExceptMSN
CVSS 8.8
CVE-2026-1138 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via ConfigExceptQQ strcpy
CVSS 8.8
CVE-2026-1137 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via formWebAuthGlobalConfig strcpy
CVSS 8.8
CVE-2026-1110 MEDIUM
cijliu librtsp <2ec1a81ad65280568a0c7c16420d7c10fde13b04 - Buffer O...
CVSS 5.3
CVE-2026-1109 MEDIUM
cijliu librtsp <2ec1a81ad65280568a0c7c16420d7c10fde13b04 - Buffer O...
CVSS 5.3
CVE-2026-1108 MEDIUM
cijliu librtsp <2ec1a81ad65280568a0c7c16420d7c10fde13b04 - Buffer O...
CVSS 5.3
CVE-2026-0892 CRITICAL
Firefox and Thunderbird < 147.0 - Memory Corruption
CVSS 9.8
Details
Vulnerabilities 13,960
Exploit Likelihood High