CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2023-21663 MEDIUM
Qualcomm Display Metadata Access Firmware - Memory Corruption
CVSS 6.7
CVE-2023-21654 MEDIUM
Qualcomm Audio Playback Firmware - Memory Corruption
CVSS 6.7
CVE-2023-39616 HIGH
AOMedia 3.0.0-3.5.0 - Invalid Memory Read in assign_frame_buffer_p
CVSS 7.5
CVE-2023-39615 MEDIUM
Libxml2 2.11.0 - Denial of Service via xmlSAX2StartElement Out-of-Bounds Read
CVSS 6.5
CVE-2023-41104 MEDIUM
libvmod-digest <1.0.3 - Memory Corruption
CVSS 6.5
CVE-2023-39984 HIGH
Hitachi EH-VIEW - Memory Corruption via Malicious File
CVSS 7.8
CVE-2023-21264 MEDIUM
Android - Local Privilege Escalation via Hypervisor Memory Access Check Bypass
CVSS 6.7
CVE-2023-3261 HIGH
Cyberpower Powerpanel Server < 2.6.9 - OS Command Injection
CVSS 7.5
CVE-2023-3824 CRITICAL
PHP <8.0.30-8.2.8 - Buffer Overflow
CVSS 9.4
CVE-2023-33867 MEDIUM
Intel RealSense <0.25.0 - Privilege Escalation
CVSS 4.4
CVE-2023-32656 MEDIUM
Intel RealSense 450 FA Firmware < 0.25.0 - Authenticated Privilege Escalation via Buffer Overflow
CVSS 5.3
CVE-2023-27506 MEDIUM
Intel Optimization for TensorFlow < 2.12 - Authenticated Privilege Escalation via Improper Buffer Restrictions
CVSS 5.5
CVE-2023-3953 MEDIUM
pro-face GP-Pro EX < 4.09.500 - Authenticated Memory Corruption via Tampered Log File
CVSS 5.3
CVE-2023-4073 HIGH
Google Chrome <115.0.5790.170 - Memory Corruption
CVSS 8.8
CVE-2023-1437 CRITICAL
Advantech WebAccess/SCADA <9.1.4 - Memory Corruption
CVSS 9.8
CVE-2023-28730 HIGH
Panasonic Control FPWIN Pro <7.6.0.3 - Memory Corruption
CVSS 7.8
CVE-2023-30431 HIGH
IBM Db2 10.5, 11.1, 11.5 - Buffer Overflow in db2set
CVSS 8.4
CVE-2023-31194 MEDIUM
Diagon v1.0.139 - Memory Corruption
CVSS 5.3
CVE-2023-21637 MEDIUM
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via System Configuration APIs
CVSS 6.7
CVE-2023-21633 MEDIUM
Qualcomm APQ8064AU Firmware - Memory Corruption via QcRilRequestImsRegisterMultiIdentityMessage
CVSS 6.7
CVE-2023-3138 HIGH
libX11 < 1.8.6 - Memory Corruption via Out-of-Bounds Array Index in InitExt.c
CVSS 7.5
CVE-2023-21167 MEDIUM
Android 13 - Denial of Service in DevicePolicyManagerService setProfileName
CVSS 5.5
CVE-2023-3110 CRITICAL
SiLabs Unify Software Development Kit < 1.3.1 - Unauthenticated Stack Buffer Overflow
CVSS 9.6
CVE-2023-0972 CRITICAL
SiLabs Z/IP Gateway SDK < 7.18.01 - Unauthenticated Stack Buffer Overflow
CVSS 9.6
CVE-2023-0969 LOW
SiLabs Z/IP Gateway SDK < 7.18.01 - Authenticated Memory Disclosure via Array Pointer Manipulation
CVSS 3.5
Details
Vulnerabilities 13,962
Exploit Likelihood High