CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2022-20601 HIGH
Android - Memory Corruption in Kernel
CVSS 7.5
CVE-2022-20599 MEDIUM
Android - Local Privilege Escalation via Missing Bounds Check
CVSS 6.7
CVE-2022-20570 MEDIUM
Android - Memory Corruption in Kernel
CVSS 5.5
CVE-2022-20560 HIGH
Android - Memory Corruption in Kernel
CVSS 7.5
CVE-2022-42846 MEDIUM
iPadOS < 15.7.2 - Denial of Service via Maliciously Crafted Video File
CVSS 5.5
CVE-2022-42844 HIGH
iPadOS < 16.2 - Sandbox Escape via Memory Handling Issue
CVSS 8.6
CVE-2022-2947 HIGH
Altair HyperView Player < 2021.1.0.27 - Memory Corruption via Buffer Overflow
CVSS 7.8
CVE-2022-25682 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption in MODEM UIM via Out-of-Range Pointer Offset
CVSS 8.4
CVE-2022-25681 HIGH
Qualcomm AQT1000 and AR8035 Firmware - Memory Corruption via Hypervisor Translation Cache Invalidation
CVSS 8.4
CVE-2022-23523 MEDIUM
linux-loader < 0.8.1 - Denial of Service via Malicious ELF Header
CVSS 4.0
CVE-2022-4291 HIGH
Avast Script Shield < 18.0.1473.0 - Heap Corruption in aswjsflt.dll
CVSS 7.7
CVE-2022-43581 HIGH
IBM Content Navigator <3.0.12 - Auth Bypass
CVSS 7.5
CVE-2022-42775 MEDIUM
Android - Denial of Service via Camera Driver Memory Corruption
CVSS 5.5
CVE-2022-39131 MEDIUM
Android - Memory Corruption in Camera Driver
CVSS 5.5
CVE-2022-24939 MEDIUM
Silicon Labs Gecko SDK and EmberZNet - Stack Overflow via Malformed Packet
CVSS 5.7
CVE-2022-41877 MEDIUM
FreeRDP < 2.9.0 - Out-of-Bounds Read via Drive Channel
CVSS 4.6
CVE-2022-29279 HIGH
SdHostDriver/SdMmcDevice - Memory Corruption
CVSS 8.2
CVE-2022-29275 HIGH
Insyde Kernel 5.0-5.4 - Memory Tampering via Untrusted Pointer in UsbCoreDxe
CVSS 8.2
CVE-2022-20947 HIGH
Cisco ASA & FTD - Unauthenticated DoS via HostScan Data Processing
CVSS 8.6
CVE-2022-3461 HIGH
Automationworx Software Suite <= 1.89 - Heap Buffer Overflow via Manipulated PC Worx or Config+ Files
CVSS 7.8
CVE-2022-24938 MEDIUM
Silabs EmberZNet - Denial of Service via Malformed Packet
CVSS 6.5
CVE-2022-24937 MEDIUM
Silicon Labs EmberZNet - Buffer Overflow
CVSS 6.5
CVE-2022-0137 HIGH
htmldoc < 1.9.15 - Heap Buffer Overflow in image_set_mask
CVSS 7.5
CVE-2022-3974 MEDIUM
Bento4 - Heap-Based Buffer Overflow in AP4_StdcFileByteStream::ReadPartial
CVSS 6.3
CVE-2022-3965 MEDIUM
ffmpeg 5.0-5.0.3 - Out-of-Bounds Read in QuickTime Graphics Video Encoder
CVSS 4.3
Details
Vulnerabilities 13,962
Exploit Likelihood High