CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,938 vulnerabilities with CWE-119
CVE-2026-28953 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-28944 HIGH
iOS and iPadOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-28941 HIGH
iOS and iPadOS < 18.7.9 and macOS < 15.7.7 - Denial of Service and Memory Disclosure via Maliciously Crafted File
CVSS 7.1
CVE-2026-28940 HIGH
iOS and iPadOS < 18.7.9 - Memory Corruption via Malicious Image Processing
CVSS 8.8
CVE-2026-28913 HIGH
macOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-28905 HIGH
iOS and iPadOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-28904 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Memory Corruption via Malicious Web Content
CVSS 7.5
CVE-2026-28903 MEDIUM
iOS and iPadOS < 18.7.9 and < 26.5 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2026-28902 MEDIUM
iOS and iPadOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 6.5
CVE-2026-28901 MEDIUM
iOS and iPadOS < 26.5 - Memory Corruption via Malicious Web Content
CVSS 4.3
CVE-2026-28847 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Memory Corruption via Malicious Web Content
CVSS 8.8
CVE-2026-8261 MEDIUM
Squirrel sqobject.cpp Load heap-based overflow
CVSS 5.9
CVE-2026-8260 HIGH
D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
CVSS 8.8
CVE-2026-8258 MEDIUM
Squirrel sqstdstring.cpp validate_format stack-based overflow
CVSS 5.3
CVE-2026-8234 HIGH
EFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflow
CVSS 8.8
CVE-2026-8213 MEDIUM
OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow
CVSS 5.3
CVE-2026-8212 MEDIUM
OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow
CVSS 5.3
CVE-2026-8186 MEDIUM
Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds
CVSS 5.3
CVE-2026-8138 HIGH
Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow
CVSS 8.8
CVE-2026-8137 HIGH
Totolink X5000R formDdns sub_458E40 buffer overflow
CVSS 8.8
CVE-2026-8088 LOW
OSGeo gdal GDapi.c GDfieldinfo out-of-bounds
CVSS 3.3
CVE-2026-8087 MEDIUM
OSGeo gdal GDapi.c GDnentries heap-based overflow
CVSS 5.3
CVE-2026-8086 MEDIUM
OSGeo gdal SWapi.c SWnentries heap-based overflow
CVSS 5.3
CVE-2026-8084 LOW
OSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-bounds
CVSS 3.3
CVE-2026-8093 HIGH
Memory safety bugs fixed in Firefox 150.0.2
CVSS 8.1
Details
Vulnerabilities 13,938
Exploit Likelihood High