CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2025-43213 MEDIUM
Safari < 18.6 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2025-43212 MEDIUM
tvOS < 18.6 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2025-43186 CRITICAL
iPadOS < 18.6 - Denial of Service via Memory Corruption
CVSS 9.8
CVE-2025-31278 HIGH
Safari < 18.6 - Memory Corruption via Malicious Web Content
CVSS 8.8
CVE-2025-31277 HIGH KEV
Safari < 18.6 - Memory Corruption via Malicious Web Content
CVSS 8.8
CVE-2025-31273 HIGH
Safari < 18.6 - Memory Corruption via Maliciously Crafted Web Content
CVSS 8.8
CVE-2025-53715 HIGH
TP-Link TL-WR841N V11 - Buffer Overflow
CVSS 7.5
CVE-2025-53714 HIGH
TP-Link TL-WR841N V11 - Buffer Overflow
CVSS 7.5
CVE-2025-53713 HIGH
TP-Link TL-WR841N V11 - Buffer Overflow
CVSS 7.5
CVE-2025-53712 HIGH
TP-Link TL-WR841N V11 - Buffer Overflow
CVSS 7.5
CVE-2025-53711 HIGH
TP-Link TL-WR841N V11 - Buffer Overflow
CVSS 7.5
CVE-2025-8246 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
CVSS 8.8
CVE-2025-8245 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMultiAPVLAN submit-url Parameter
CVSS 8.8
CVE-2025-8244 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMapDelDevice macstr Parameter
CVSS 8.8
CVE-2025-8243 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via devicemac1 Parameter
CVSS 8.8
CVE-2025-8242 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
CVSS 8.8
CVE-2025-8184 HIGH
D-Link DIR-513 < 1.10 - Stack-Based Buffer Overflow via formSetWanL2TPtriggers HTTP POST Request
CVSS 8.8
CVE-2025-8180 HIGH
Tenda CH22 1.0.0.1 - Buffer Overflow via old_account Parameter in deleteUserName
CVSS 8.8
CVE-2025-8178 HIGH
Tenda AC10 16.03.10.13 - Heap-Based Buffer Overflow via device1D Argument
CVSS 8.8
CVE-2025-8177 MEDIUM
libtiff < 4.7.0 - Buffer Overflow in setrow Function
CVSS 5.3
CVE-2025-8176 MEDIUM
libtiff < 4.7.0 - Use-After-Free in get_histogram Function
CVSS 5.3
CVE-2025-8170 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow in MQTT Packet Handler via tcpcheck_net serverIp Argument
CVSS 8.8
CVE-2025-8169 HIGH
D-Link DIR-513 1.10 - Buffer Overflow via formSetWanPPTPpath curTime Parameter
CVSS 8.8
CVE-2025-8168 HIGH
D-Link DIR-513 1.10 - Buffer Overflow via curTime in formSetWanPPPoE
CVSS 8.8
CVE-2025-8160 HIGH
Tenda AC20 <= 16.03.08.12 - Buffer Overflow via SetSysTimeCfg timeZone Parameter
CVSS 8.8
Details
Vulnerabilities 13,962
Exploit Likelihood High