CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2023-35957 HIGH
GTKWave 3.3.115 - Heap-Based Buffer Overflow in fstReaderIterBlocks2 VCDATA Parsing
CVSS 7.8
CVE-2023-35956 HIGH
GTKWave 3.3.115 - Heap-Based Buffer Overflow in fstReaderIterBlocks2 VCDATA Parsing
CVSS 7.8
CVE-2023-35955 HIGH
GTKWave 3.3.115 - Heap-Based Buffer Overflow in VCDATA Parsing via Malicious FST File
CVSS 7.8
CVE-2023-34436 HIGH
GTKWave 3.3.115 - Out-of-Bounds Write in LXT2 num_time_table_entries
CVSS 7.8
CVE-2023-34087 HIGH
GTKWave 3.3.115 - Arbitrary Code Execution via EVCD File Parsing
CVSS 7.8
CVE-2023-46837 LOW
Xen < 4.16 - Memory Corruption via Cache Cleaning Helper Arithmetic Overflow
CVSS 3.3
CVE-2023-34321 LOW
Xen < 4.16 - Memory Corruption via Cache Helper Arithmetic Overflow
CVSS 3.3
CVE-2023-41779 MEDIUM
ZTE ZXCLOUD iRAI < 7.23.32 - Authenticated Denial of Service via Illegal Memory Access
CVSS 4.4
CVE-2023-32887 HIGH
MediaTek NR15 NR16 NR17 - Remote Denial of Service via Missing Bounds Check in Modem IMS Stack
CVSS 7.5
CVE-2023-32885 MEDIUM
Android - Memory Corruption in Display DRM due to Missing Bounds Check
CVSS 6.7
CVE-2023-32884 MEDIUM
Android - Local Privilege Escalation via Incorrect Bounds Check in netdagent
CVSS 6.7
CVE-2023-7104 MEDIUM
SQLite < 3.43.0 - Heap-Based Buffer Overflow in sessionReadRecord
CVSS 5.5
CVE-2023-42906 HIGH
macOS 14.0-14.1 - Memory Corruption via Maliciously Crafted File
CVSS 7.8
CVE-2023-6560 MEDIUM
Linux Kernel < 6.6 - Out-of-Bounds Memory Access in io_uring SQ/CQ Rings
CVSS 5.5
CVE-2023-33106 HIGH KEV
Qualcomm AR8035 and related firmware - Memory Corruption via IOCTL_KGSL_GPU_AUX_COMMAND AUX Sync Points
CVSS 8.4
CVE-2023-33092 HIGH
Qualcomm FastConnect and AQT1000 Firmware - Memory Corruption in Bluetooth Pin Processing
CVSS 8.4
CVE-2023-33079 HIGH
Qualcomm AR8035 and related firmware - Memory Corruption in Audio ADSP Recording
CVSS 7.8
CVE-2023-28587 HIGH
Qualcomm Modem and Networking Firmware - Memory Corruption in BT Controller
CVSS 7.8
CVE-2023-28586 MEDIUM
Qualcomm Modem and Platform Firmware - Information Disclosure via ELF Metadata Symbol Access
CVSS 6.0
CVE-2023-28585 HIGH
Qualcomm 315 5G IoT Modem Firmware - Memory Corruption in TEE Kernel ELF Segment Loading
CVSS 8.2
CVE-2023-28551 HIGH
Qualcomm Modem Firmware - Memory Corruption in UTILS
CVSS 7.8
CVE-2023-28550 HIGH
Qualcomm Modem Firmware - Memory Corruption in MPP Performance
CVSS 7.8
CVE-2023-21634 MEDIUM
Radio Interface Layer - Memory Corruption
CVSS 6.7
CVE-2023-45168 HIGH
IBM AIX 7.2-7.3 and VIOS 3.1 - Local Command Execution via invscout Command
CVSS 8.4
CVE-2023-49701 HIGH
ASR1803 and ASR1806 Firmware - Memory Corruption in SIM Management during USIM Phase2 Initialization
CVSS 7.2
Details
Vulnerabilities 13,962
Exploit Likelihood High