CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,938 vulnerabilities with CWE-119
CVE-2026-8974 HIGH
Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
CVSS 8.8
CVE-2026-8973 HIGH
Firefox and Thunderbird < 151 - Memory Corruption
CVSS 8.8
CVE-2026-8959 CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS 9.6
CVE-2026-8954 HIGH
Incorrect boundary conditions, integer overflow in the Audio/Video component
CVSS 7.5
CVE-2026-8946 HIGH
Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-8836 CRITICAL
lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow
CVSS 9.8
CVE-2026-45495 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-8780 MEDIUM
omec-project amf NGAP Message dispatcher.go memory corruption
CVSS 4.3
CVE-2026-8779 MEDIUM
omec-project amf handler.go NGSetupRequest memory corruption
CVSS 4.3
CVE-2026-8776 HIGH
Edimax BR-6428NS POST Request formPPTPSetup buffer overflow
CVSS 8.8
CVE-2026-8775 HIGH
Edimax BR-6428NS POST Request formL2TPSetup buffer overflow
CVSS 8.8
CVE-2026-8764 HIGH
H3C Magic B3 aspForm UpdateWanParams buffer overflow
CVSS 7.2
CVE-2026-8746 MEDIUM
Open5GS NRF nghttp2-server.c discover_handler use after free
CVSS 4.3
CVE-2026-8733 MEDIUM
Investintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflow
CVSS 6.3
CVE-2026-8556 LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via ANGLE Implementation
CVSS 3.1
CVE-2026-8545 LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via Compositing Object Corruption
CVSS 3.1
CVE-2026-8391 MEDIUM
Firefox < 150.0.3 - Memory Corruption in JavaScript Engine
CVSS 5.3
CVE-2026-8389 HIGH
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 8.8
CVE-2026-8388 MEDIUM
Incorrect boundary conditions in the JavaScript Engine: JIT component
CVSS 6.5
CVE-2026-8349 MEDIUM
omec-project amf NGAP Message memory corruption
CVSS 4.3
CVE-2026-43658 HIGH
iOS and iPadOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-39870 HIGH
macOS - Memory Corruption
CVSS 7.5
CVE-2026-28990 HIGH
iOS and iPadOS < 26.5 - Memory Corruption via Maliciously Crafted Image
CVSS 7.5
CVE-2026-28977 MEDIUM
watchOS < 26.5 - Denial of Service via Maliciously Crafted File
CVSS 6.2
CVE-2026-28955 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Memory Corruption via Malicious Web Content
CVSS 8.8
Details
Vulnerabilities 13,938
Exploit Likelihood High