CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,960 vulnerabilities with CWE-119
CVE-2025-46302 MEDIUM
macOS <15.7.4-iPadOS <18.7.5-<macOS Sonoma <14.8.4 - Use After Free
CVSS 5.7
CVE-2025-46301 MEDIUM
macOS <15.7.4-iPadOS <18.7.5-macOS <14.8.4 - Use After Free
CVSS 5.7
CVE-2025-46300 MEDIUM
macOS <15.7.4-iPadOS <18.7.5-macOS <14.8.4 - Use After Free
CVSS 5.7
CVE-2025-22885 MEDIUM
TDX Module - Privilege Escalation via Improper Buffer Restrictions
CVSS 4.7
CVE-2025-15570 MEDIUM
ckolivas lrzip <0.651 - Use After Free
CVSS 5.3
CVE-2025-15555 HIGH
Open5GS < 2.7.6 - Stack-Based Buffer Overflow in VoLTE Cx-Test hss_ogs_diam_cx_mar_cb
CVSS 7.3
CVE-2025-15538 MEDIUM
assimp < 6.0.2 - Use-After-Free in LWOImporter::FindUVChannels
CVSS 5.3
CVE-2025-15537 MEDIUM
mapnik < 4.2.0 - Heap-Based Buffer Overflow in dbf_file::string_value
CVSS 5.3
CVE-2025-15536 MEDIUM
OpenCC < 1.1.9 - Heap-Based Buffer Overflow in MaxMatchSegmentation
CVSS 5.3
CVE-2025-15533 MEDIUM
raylib < 2026-01-01 - Heap-Based Buffer Overflow in GenImageFontAtlas
CVSS 5.3
CVE-2025-65396 MEDIUM
Blurams Flare Camera <24.1114.151.929 - Info Disclosure
CVSS 6.1
CVE-2025-58409 LOW
ImaginationTech DDK < 25.3 - Arbitrary Physical Memory Write via GPU System Calls
CVSS 3.5
CVE-2025-15506 LOW
OpenColorIO < 2.5.1 - Out-of-Bounds Read in ConvertToRegularExpression
CVSS 3.3
CVE-2025-46298 MEDIUM
Safari < 26.2 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2025-15462 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via ConfigAdvideo timestart Parameter
CVSS 8.8
CVE-2025-15461 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via selDateType Argument in formTaskEdit
CVSS 8.8
CVE-2025-15460 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via EncryptionMode Argument in formPptpClientConfig
CVSS 8.8
CVE-2025-15459 HIGH
UTT 520W < 1.7.7-180627 - Buffer Overflow via formUser strcpy
CVSS 8.8
CVE-2025-15431 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via formFtpServerDirConfig Filename Parameter
CVSS 8.8
CVE-2025-15430 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via formFtpServerShareDirSelcet oldfilename Parameter
CVSS 8.8
CVE-2025-15429 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via formConfigCliForEngineerOnly addCommand Parameter
CVSS 8.8
CVE-2025-15428 HIGH
UTT 512W < 1.7.7-171114 - Buffer Overflow via Remote Control Profile Argument
CVSS 8.8
CVE-2025-15413 MEDIUM
wasm3 < 0.5.0 - Memory Corruption in op_SetSlot_i32/op_CallIndirect
CVSS 5.3
CVE-2025-15412 MEDIUM
WebAssembly wabt <= 1.0.39 - Out-of-Bounds Read in wasm-decompile VarName Function
CVSS 5.3
CVE-2025-15411 MEDIUM
WebAssembly wabt < 1.0.39 - Memory Corruption in wasm-decompile AST InsertNode
CVSS 5.3
Details
Vulnerabilities 13,960
Exploit Likelihood High