CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2024-23369 HIGH
Qualcomm Snapdragon and WSA/WCN/WCD Firmware - Memory Corruption via FRS/UDS Buffer Length
CVSS 7.8
CVE-2024-21455 HIGH
Qualcomm IOCTL Calls Firmware - Memory Corruption
CVSS 7.8
CVE-2024-9403 HIGH
Firefox < 131 - Memory Corruption
CVSS 7.3
CVE-2024-9402 CRITICAL
Firefox < 131 and ESR < 128.3 - Memory Corruption
CVSS 9.8
CVE-2024-9401 CRITICAL
Firefox < 131 and ESR < 128.3 and ESR < 115.16 - Memory Corruption
CVSS 9.8
CVE-2024-9400 HIGH
Firefox < 131 and ESR < 128.3 - Memory Corruption during JIT Compilation
CVSS 8.8
CVE-2024-9396 HIGH
Firefox < 131 and ESR < 128.3 - Memory Corruption via Structured Clone
CVSS 8.8
CVE-2024-22170 CRITICAL
Western Digital My Cloud <5.29.102. - Buffer Overflow
CVE-2024-38269 MEDIUM
Zyxel VMG8825-T50K <5.50(ABOM.8)C0 - Memory Corruption
CVSS 4.9
CVE-2024-38268 MEDIUM
Zyxel VMG8825-T50K <5.50(ABOM.8)C0 - Memory Corruption
CVSS 4.9
CVE-2024-38267 MEDIUM
Zyxel VMG8825-T50K <5.50(ABOM.8)C0 - Memory Corruption
CVSS 4.9
CVE-2024-38266 MEDIUM
Zyxel VMG8825-T50K <5.50(ABOM.8)C0 - Memory Corruption
CVSS 4.9
CVE-2024-7024 CRITICAL
Google Chrome < 126.0.6478.54 - Sandbox Escape via V8 Implementation Flaw
CVSS 9.6
CVE-2024-45810 MEDIUM
envoyproxy/envoy < 1.28.7 - Denial of Service via HTTP Async Client sendLocalReply
CVSS 6.5
CVE-2024-45809 MEDIUM
Envoy 1.29.0-1.29.8 - Denial of Service via JWT Filter Route Cache Clearing
CVSS 5.3
CVE-2024-27879 HIGH
iPadOS < 17.7 - Denial of Service via Memory Buffer Overflow
CVSS 7.5
CVE-2024-43756 HIGH
Adobe Photoshop < 24.7.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-39380 HIGH
Adobe After Effects < 23.6.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-45181 HIGH
WibuKey < 6.70 - Kernel Memory Corruption via Crafted Packet Bounds Check Bypass
CVSS 7.8
CVE-2024-42425 LOW
Dell Precision Rack <2.22.2 - Info Disclosure
CVSS 3.8
CVE-2024-8573 HIGH
TOTOLINK AC1200 T8/T10 4.1.5cu.861_B20230220/4.1.8cu.5207 Buffer Overflow via setParentalRules
CVSS 8.8
CVE-2024-8389 CRITICAL
Firefox < 130 - Memory Corruption
CVSS 9.8
CVE-2024-8387 CRITICAL
Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2 - Memory Corruption
CVSS 9.8
CVE-2024-33016 MEDIUM
Qualcomm QCN/QCS/Snapdragon Firmware - Memory Corruption via Invalid Firehose Patch Command
CVSS 6.8
CVE-2024-45169 CRITICAL
UCI IDOL 2 <2.12 - DoS/Code Execution
CVSS 9.8
Details
Vulnerabilities 13,962
Exploit Likelihood High