CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2024-7972 HIGH
Google Chrome < 128.0.6613.84 - Out of Bounds Memory Access in V8
CVSS 8.8
CVE-2024-7966 HIGH
Google Chrome < 128.0.6613.84 - Out of Bounds Memory Access in Skia
CVSS 8.8
CVE-2024-7795 HIGH
Autel MaxiCharger AC Elite Business C50 < 1.36.00 - Unauthenticated Stack-Based Buffer Overflow
CVSS 8.8
CVE-2024-44067 HIGH
T-Head XuanTie C910 and C920 CPUs - Arbitrary Physical Memory Write via GhostWrite
CVSS 8.4
CVE-2024-20082 CRITICAL
MediaTek NR15 NR16 NR17 - Remote Code Execution via Missing Bounds Check
CVSS 9.8
CVE-2024-38218 HIGH
Microsoft Edge Chromium < 127.0.2651.98 - Memory Corruption
CVSS 8.4
CVE-2024-21980 HIGH
AMD EPYC 7003 Series Firmware < milanpi_1.0.0.d - Memory Corruption via SNP Firmware Write Operations
CVSS 7.9
CVE-2024-23356 HIGH
Qualcomm WSA8845H and WSA8845 Firmware - Memory Corruption during Session Sign Renewal
CVSS 7.8
CVE-2024-23355 HIGH
Qualcomm WSA8845H and other Firmware - Memory Corruption via Keymaster Shared Key Import
CVSS 7.8
CVE-2024-21481 HIGH
Qualcomm AR8035 and FastConnect Firmware - Memory Corruption in Resource Manager
CVSS 8.4
CVE-2024-7441 HIGH
Vivotek SD9364 VVTK-0103f - Stack-Based Buffer Overflow in httpd via Content-Length Argument
CVSS 8.8
CVE-2024-7439 HIGH
Vivotek CC8160 VVTK-0100d - Stack-Based Buffer Overflow in httpd via Content-Length Argument
CVSS 8.8
CVE-2024-36434 HIGH
Supermicro X11DPH-T/X11DPH-Tq/X11DPH-i <4.4 - SMM Callout
CVSS 7.5
CVE-2024-36433 HIGH
Supermicro X11DPH-T/X11DPH-Tq/X11DPH-i <4.4 - Memory Corruption
CVSS 7.5
CVE-2024-40988 MEDIUM
Linux Kernel < 4.19.317 Buffer Overflow in Radeon DPM
CVSS 5.5
CVE-2024-6236 HIGH
Citrix NetScaler Console, Agent, and SDX 13.0-58.30-13.0-92.31 - Denial of Service
CVSS 7.5
CVE-2024-38104 HIGH
Windows Fax Service - Remote Code Execution
CVSS 8.8
CVE-2024-21482 MEDIUM
Qualcomm IPQ6018 Firmware - Memory Corruption via Secure Boot Bypass
CVSS 6.8
CVE-2024-0153 HIGH
Arm 5th Gen & Valhall GPU Firmware r29p0-r46p0 Memory Corruption via GPU Operations
CVSS 7.8
CVE-2024-20077 HIGH
MediaTek LR12A - Remote Denial of Service via Incorrect Error Handling
CVSS 7.5
CVE-2024-20076 HIGH
MediaTek LR12A - Denial of Service via Incorrect Error Handling
CVSS 7.5
CVE-2024-37676 HIGH
htop-dev htop <2.20 - Memory Corruption
CVSS 8.4
CVE-2024-30090 HIGH
Microsoft Streaming Service - Privilege Escalation
CVSS 7.0
CVE-2024-27857 HIGH
Apple iOS, macOS, tvOS, and visionOS - Remote Code Execution via Out-of-Bounds Access
CVSS 7.8
CVE-2024-27851 HIGH
Safari < 17.5 - Remote Code Execution via Malicious Web Content
CVSS 8.8
Details
Vulnerabilities 13,962
Exploit Likelihood High