CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2024-24561 CRITICAL
vyperlang/vyper < 0.3.10 and pypi/vyper < 0.4.0 - Memory Buffer Overflow via Slice Bounds Check
CVSS 9.8
CVE-2024-21916 HIGH
Rockwell Automation ControlLogix and GuardLogix - Denial of Service
CVSS 8.6
CVE-2024-1112 HIGH
Resource Hacker <3.6.0.92 - Buffer Overflow
CVSS 7.3
CVE-2024-23617 CRITICAL
Symantec Data Center Security Server < 14.0.2 - Unauthenticated Remote Code Execution via Crafted Document
CVSS 9.6
CVE-2024-23616 CRITICAL
Symantec Server Management Suite < 7.9 - Unauthenticated Remote Code Execution via Buffer Overflow
CVSS 10.0
CVE-2024-23615 CRITICAL
Symantec Messaging Gateway < 10.5 - Unauthenticated Remote Code Execution via Stack Buffer Overflow
CVSS 10.0
CVE-2024-23614 CRITICAL
Symantec Messaging Gateway < 9.5 - Unauthenticated Stack Buffer Overflow
CVSS 10.0
CVE-2024-23613 CRITICAL
Symantec Deployment Solution 7.9 - Unauthenticated Remote Code Execution via UpdateComputer Token Parsing
CVSS 10.0
CVE-2024-0744 HIGH
Firefox < 122.0 - Use-After-Free via JIT Compilation
CVSS 7.5
CVE-2024-23213 HIGH
Safari < 17.3 - Remote Code Execution via Memory Corruption
CVSS 8.8
CVE-2024-0774 MEDIUM
Any-Capture Any Sound Recorder 2.93 - Memory Corruption
CVSS 5.3
CVE-2024-0772 MEDIUM
Nsasoft ShareAlarmPro 2.1.4 - Memory Corruption
CVSS 5.3
CVE-2024-0771 MEDIUM
Nsasoft Product Key Explorer <4.0.9 - Memory Corruption
CVSS 5.3
CVE-2024-0645 HIGH
Explorer++ <1.3.5.531 - Buffer Overflow
CVSS 7.3
CVE-2024-0532 HIGH
Tenda A15 15.13.07.13 - Buffer Overflow
CVSS 7.2
CVE-2024-0429 HIGH
Hex Workshop 6.7 - Denial of Service via Command Line File Argument
CVSS 7.3
CVE-2023-31317 HIGH
Amd Radeon™ RX 6000 Series Graphics Products - Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2023-31364 HIGH
AMD EPYC Processors - Denial of Service via IOMMU Direct Memory Write Flood
CVE-2023-31351 MEDIUM
AMD EPYC 7003/9004/8004 Series Processors - Memory Access Control Bypass via IOMMU
CVSS 5.3
CVE-2023-49618 HIGH
Intel(R) System Security Report and System Resources Defense - Priv...
CVSS 7.5
CVE-2023-48267 HIGH
Intel System Security Report - Privilege Escalation
CVSS 7.9
CVE-2023-31352 MEDIUM
AMD EPYC 9004 Processors - Unauthorized Memory Read via SEV Firmware
CVSS 6.0
CVE-2023-46586 CRITICAL
weborf 0.17-0.20 - Buffer Overflow in CGI Path Handling
CVSS 9.1
CVE-2023-6362 HIGH
WinHex 16.1 SR-1 and 20.4 - Buffer Overflow via Long Filename Argument
CVSS 7.3
CVE-2023-6361 HIGH
WinHex 16.1 SR-1 and 20.4 - Buffer Overflow via Long Filename Argument
CVSS 7.3
Details
Vulnerabilities 13,962
Exploit Likelihood High