CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,960 vulnerabilities with CWE-119
CVE-2026-0891 HIGH
Firefox and Thunderbird < 147 - Memory Corruption
CVSS 8.1
CVE-2026-0886 MEDIUM
Firefox < 115.32.0, 140.7-140.*, >=147 - Memory Corruption in Graphics Component
CVSS 5.3
CVE-2026-0879 CRITICAL
Firefox < 115.32.0, 140.7-140.*, <147.0, >=147 - Sandbox Escape via Graphics Component Boundary Condition
CVSS 9.8
CVE-2026-0878 HIGH
Firefox < 147.0 and 140.7-140.* - Sandbox Escape via CanvasWebGL Boundary Condition Mismanagement
CVSS 8.0
CVE-2026-0841 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via formPictureUrl importpictureurl Parameter
CVSS 8.8
CVE-2026-0840 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via timestart Argument in formConfigNoticeConfig
CVSS 8.8
CVE-2026-0839 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via wepkey1 Argument in APSecurity Function
CVSS 8.8
CVE-2026-0838 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via SSID Parameter in ConfigWirelessBase
CVSS 8.8
CVE-2026-0837 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via GroupName Argument in formFireWall
CVSS 8.8
CVE-2026-0836 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via ssid Argument in formConfigFastDirectionW
CVSS 8.8
CVE-2026-0822 MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_sort
CVSS 6.3
CVE-2026-0821 HIGH
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor
CVSS 7.3
CVE-2026-0640 HIGH
Tenda AC23 16.03.07.52 - Buffer Overflow via PowerSaveSet Time Parameter
CVSS 8.8
CVE-2026-21634 MEDIUM
UniFi Protect < 6.2.72 - Denial of Service via Discovery Protocol Overflow
CVSS 6.5
CVE-2025-62623 HIGH
ESXi 8.x And ESXi 9.x Hosts Using AMD-Pensando Dpu Products - Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2025-36510 MEDIUM
Display Virtualization For Windows OS Driver Software - Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2025-47408 HIGH
Untrusted Pointer Dereference in Power Optimization Firmware
CVSS 7.8
CVE-2025-47405 HIGH
Untrusted Pointer Dereference in Camera
CVSS 7.8
CVE-2025-43264 HIGH
Apple macOS <15.6 - Memory Corruption
CVSS 8.8
CVE-2025-20073 LOW
Intel UEFI DXE Module - Info Disclosure
CVE-2025-20005 MEDIUM
Intel UEFI Firmware - Privilege Escalation
CVE-2025-12345 HIGH
LLM-Claw 0.1.0-0.1.1a-p1 - Buffer Overflow
CVSS 8.8
CVE-2025-61144 HIGH
libtiff < 4.7.1 - Stack Overflow via readSeparateStripsIntoBuffer
CVSS 7.3
CVE-2025-46305 MEDIUM
macOS <15.7.4-iPadOS <18.7.5-macOS <14.8.4 - Use After Free
CVSS 5.7
CVE-2025-46303 MEDIUM
macOS <15.7.4-iPadOS <18.7.5-macOS <14.8.4 - Use After Free
CVSS 5.7
Details
Vulnerabilities 13,960
Exploit Likelihood High