CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2022-43762 HIGH
B&R APROL < R 4.2-07 - Memory Corruption
CVSS 7.5
CVE-2022-41342 MEDIUM
Intel(R) C++ Compiler Classic <2021.7.1 - Privilege Escalation
CVSS 6.0
CVE-2022-32512 MEDIUM
CanBRASS < 7.5.1 - Remote Code Execution via Memory Buffer Overflow
CVSS 5.3
CVE-2022-42418 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via TIF File Parsing
CVSS 7.8
CVE-2022-42396 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via XPS File Parsing
CVSS 7.8
CVE-2022-42377 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via U3D File Parsing
CVSS 7.8
CVE-2022-34399 MEDIUM
Dell Alienware m17 R5 BIOS < 1.2.2 - Authenticated Buffer Overflow via SMRAM Input
CVSS 5.1
CVE-2022-42286 MEDIUM
NVIDIA DGX A100 SBIOS < 1.18 - Code Execution or Denial of Service in Bds
CVSS 6.0
CVE-2022-42278 HIGH
NVIDIA BMC < 00.19.07 - Authenticated Memory Corruption via SPX REST API
CVSS 7.2
CVE-2022-3161 HIGH
Siemens JT2Go < 14.1.0.5 and Teamcenter Visualization 13.3.0-13.3.0.8 - Remote Code Execution via Crafted PDF File
CVSS 7.8
CVE-2022-3628 MEDIUM
Linux Kernel - Buffer Overflow in Broadcom Full MAC Wi-Fi Driver via Malicious USB Device
CVSS 6.6
CVE-2022-23813 MEDIUM
AMD MilanPi-SP3 and RomePi Firmware < 1.0.0.9 - Memory Integrity Loss via SNP Policy Enforcement
CVSS 5.3
CVE-2022-38105 HIGH
Asus RT-AX82U 3.0.0.4 - Info Disclosure
CVSS 7.5
CVE-2022-47967 HIGH
Siemens Solid Edge < V2023 MP1 - Remote Code Execution via Malicious PAR ASM or DFT File Parsing
CVSS 7.8
CVE-2022-47935 HIGH
Siemens JT Open <11.1.1.0, JT Utilities <13.1.1.0, Solid Edge <SE2023 - RCE via Crafted JT File
CVSS 7.8
CVE-2022-3715 HIGH
GNU Bash 5.1-5.1.7 - Heap-Based Buffer Overflow in Parameter Transform
CVSS 7.8
CVE-2022-42264 HIGH
NVIDIA GPU Display Driver 470-470.161.03 - Use-After-Free in Kernel Mode Layer
CVSS 7.1
CVE-2022-2584 HIGH
IPLD go-codec-dagpb < 1.3.1 - Panic via Invalid Blocks
CVSS 7.5
CVE-2022-31748 CRITICAL
Firefox < 101 - Memory Corruption
CVSS 9.8
CVE-2022-31747 CRITICAL
Firefox < 101 and Firefox ESR < 91.10 - Memory Corruption
CVSS 9.8
CVE-2022-31740 HIGH
Firefox < 101.0 and Firefox ESR < 91.10 - Memory Corruption via WASM Assembly Generation
CVSS 8.8
CVE-2022-4639 MEDIUM
sslh - Format String Vulnerability in Packet Dumping Handler
CVSS 5.6
CVE-2022-4603 MEDIUM
ppp < 2.5.0 - Improper Validation of Array Index in pppdump dumpppp Function
CVSS 4.3
CVE-2022-42529 CRITICAL
Android - Memory Corruption in Kernel
CVSS 9.8
CVE-2022-20602 HIGH
Android - Memory Corruption in Kernel
CVSS 7.5
Details
Vulnerabilities 13,962
Exploit Likelihood High