CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2024-21961 MEDIUM
AMD EPYC 7002 Series Processors - Denial of Service via PCIe Link Memory Buffer Overflow
CVE-2024-44238 HIGH
iPadOS < 18.1 - Memory Corruption via Coprocessor Bounds Check Bypass
CVSS 7.8
CVE-2024-9684 HIGH
FreyrSCADA/IEC-60870-5-104 server <21.06.008 - DoS
CVSS 7.5
CVE-2024-36292 HIGH
Intel(R) Data Center GPU Flex Series - DoS
CVSS 7.3
CVE-2024-45570 MEDIUM
Qualcomm Firmware - Memory Corruption during IO Configuration Processing
CVSS 6.6
CVE-2024-45064 HIGH
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Buffer Overflow
CVSS 8.5
CVE-2024-13941 MEDIUM
ouch < 0.4.0 - Memory Corruption in zip.rs convert_zip_date_time Function
CVSS 5.3
CVE-2024-13903 MEDIUM
quickjs-ng QuickJS < 0.9.0 - Stack-Based Buffer Overflow in JS_GetRuntime
CVSS 4.3
CVE-2024-54551 HIGH
Safari < 17.6 - Denial of Service via Memory Handling Issue
CVSS 7.5
CVE-2024-52923 HIGH
Samsung Exynos Modems (Multiple) - DoS via DL NAS Transport Message Decoding
CVSS 7.5
CVE-2024-53034 HIGH
Qualcomm FastConnect 6900/7800, SC8380XP, WCD9380/9385, WSA8840/8845/8845H Firmware Memory Corruption
CVSS 7.8
CVE-2024-53033 HIGH
Qualcomm FastConnect and Related Firmware - Memory Corruption via Escape Call
CVSS 7.8
CVE-2024-43060 HIGH
Qualcomm Firmware - Memory Corruption during Voice Activation
CVSS 7.8
CVE-2024-45421 HIGH
Zoom Meeting SDK < 6.2.0 - Authenticated Buffer Overflow via Network Access
CVSS 8.5
CVE-2024-31155 HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2024-21859 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.3
CVE-2024-49840 HIGH
Qualcomm FastConnect and Multiple Firmware - Memory Corruption via IOCTL FIPS Validation
CVSS 7.8
CVE-2024-45584 HIGH
Qualcomm FastConnect and AR8035/QAM8255P/QAM8295P Firmware - Memory Corruption
CVSS 7.8
CVE-2024-45573 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-11611 HIGH
AutomationDirect C-More EA9 Firmware < 6.78 - Remote Code Execution via EAP9 File Parsing
CVSS 7.8
CVE-2024-11610 HIGH
AutomationDirect C-More EA9 Firmware < 6.78 - Remote Code Execution via EAP9 File Parsing
CVSS 7.8
CVE-2024-10498 MEDIUM
Schneider Electric PowerLogic HDPM6000 - Memory Corruption via Modbus Write Packets
CVSS 6.5
CVE-2024-11139 MEDIUM
EcoStruxure Power Build Rapsody < v2.5.2 NL/FR/ES/INT - Local Code Execution via Malicious Project File
CVE-2024-52333 HIGH
OFFIS DCMTK <3.6.8 - Buffer Overflow
CVSS 8.4
CVE-2024-47796 HIGH
OFFIS DCMTK <3.6.8 - Buffer Overflow
CVSS 8.4
Details
Vulnerabilities 13,962
Exploit Likelihood High