CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,732 vulnerabilities with CWE-119
CVE-2026-5567 HIGH
Tenda M3 Destination setAdvPolicyData buffer overflow
CVSS 8.8
CVE-2026-5566 HIGH
UTT HiPER 1250GW formNatStaticMap strcpy buffer overflow
CVSS 8.8
CVE-2026-5550 HIGH
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
CVSS 8.8
CVE-2026-5548 HIGH
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
CVSS 8.8
CVE-2026-5544 HIGH
UTT HiPER 1250GW formRemoteControl stack-based overflow
CVSS 8.8
CVE-2026-5475 MEDIUM
NASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption
CVSS 5.5
CVE-2026-5474 MEDIUM
NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow
CVSS 6.3
CVE-2026-5350 HIGH
Trendnet TEW-657BRM setup.cgi update_pcdb stack-based overflow
CVSS 8.8
CVE-2026-5349 HIGH
Trendnet TEW-657BRM setup.cgi add_apcdb stack-based overflow
CVSS 8.8
CVE-2026-5342 MEDIUM
LibRaw TIFF/NEF decoders_libraw.cpp nikon_load_padded_packed_raw out-of-bounds
CVSS 5.3
CVE-2026-5245 MEDIUM
Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow
CVSS 5.6
CVE-2026-5244 HIGH
Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow
CVSS 7.3
CVE-2026-5318 MEDIUM
LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write
CVSS 4.3
CVE-2026-5317 MEDIUM
Nothings stb stb_vorbis.c start_decoder out-of-bounds write
CVSS 6.3
CVE-2026-5315 MEDIUM
Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds
CVSS 4.3
CVE-2026-5314 MEDIUM
Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds
CVSS 4.3
CVE-2026-34159 CRITICAL
llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend
CVSS 9.8
CVE-2026-5236 MEDIUM
Axiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow
CVSS 5.3
CVE-2026-5235 MEDIUM
Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow
CVSS 5.3
CVE-2026-5214 HIGH
D-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow
CVSS 8.8
CVE-2026-5213 HIGH
D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
CVSS 8.8
CVE-2026-5212 HIGH
D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow
CVSS 8.8
CVE-2026-5211 HIGH
D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow
CVSS 8.8
CVE-2026-5204 HIGH
Tenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow
CVSS 8.8
CVE-2026-5186 MEDIUM
Nothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double free
CVSS 5.3
Details
Vulnerabilities 13,732
Exploit Likelihood High