CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,962 vulnerabilities with CWE-119
CVE-2022-3649 LOW
Linux Kernel < 4.9.331 - Use-After-Free in nilfs_new_inode
CVSS 3.1
CVE-2022-3640 MEDIUM
Linux Kernel 4.9.326-4.9.333 - Use-After-Free in Bluetooth L2CAP Connection Deletion
CVSS 5.5
CVE-2022-3636 MEDIUM
Linux Kernel - Use-After-Free in Ethernet Handler via __mtk_ppe_check_skb
CVSS 5.5
CVE-2022-3635 MEDIUM
Linux Kernel 2.6.12-4.9.325 - Use-After-Free in IPsec tst_timer Function
CVSS 5.5
CVE-2022-3625 MEDIUM
Linux Kernel 4.19-5.4.210 - Use-After-Free in devlink_param_set/devlink_param_get
CVSS 4.6
CVE-2022-3620 MEDIUM
Exim 4.95-4.96 - Use-After-Free in DMARC Handler
CVSS 5.6
CVE-2022-27625 CRITICAL
Synology DiskStation Manager < 7.1.1-42962-2 - Remote Code Execution via OOB Management Message Processing
CVSS 10.0
CVE-2022-27624 CRITICAL
Synology DiskStation Manager < 7.1.1-42962-2 - Remote Code Execution via OOB Management Packet Decryption
CVSS 10.0
CVE-2022-33210 HIGH
Snapdragon Auto - Memory Corruption
CVSS 8.4
CVE-2022-25662 MEDIUM
Qualcomm APQ8096AU and other Snapdragon Firmware - Information Disclosure via Untrusted Pointer Dereference
CVSS 5.3
CVE-2022-25661 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Untrusted Pointer Dereference
CVSS 8.4
CVE-2022-3595 LOW
Linux Kernel < 6.1 - Use-After-Free in CIFS Handler sess_free_buffer
CVSS 3.5
CVE-2022-3565 MEDIUM
Linux Kernel 2.6.27-4.9.330 - Use-After-Free in Bluetooth l1oip_core.c del_timer
CVSS 4.6
CVE-2022-3564 MEDIUM
Linux Kernel 3.6-4.9.332 - Use-After-Free in Bluetooth L2CAP SDU Reassembly
CVSS 5.5
CVE-2022-3559 MEDIUM
Exim < 4.97 - Use-After-Free in Regex Handler
CVSS 4.6
CVE-2022-3550 MEDIUM
X.org Server < 21.1.6 - Buffer Overflow in _GetCountedString
CVSS 5.5
CVE-2022-3545 MEDIUM
Linux Kernel 4.11-4.14.303 - Use-After-Free in IPsec area_cache_get Function
CVSS 5.5
CVE-2022-3541 MEDIUM
Linux Kernel 5.19-5.19.16 - Use-After-Free in spl2sw_nvmem_get_mac_address
CVSS 5.5
CVE-2022-3534 MEDIUM
Linux Kernel - Use-After-Free in btf_dump_name_dups Function
CVSS 5.5
CVE-2022-3523 MEDIUM
Linux Kernel - Use-After-Free in Driver Handler
CVSS 5.3
CVE-2022-38690 MEDIUM
Android - Denial of Service via Camera Driver Memory Corruption
CVSS 5.5
CVE-2022-34391 HIGH
Dell Alienware Area-51 R5 and R4 Firmware < 2.0.6 - Authenticated Arbitrary Code Execution in SMRAM via SMI
CVSS 7.5
CVE-2022-32491 MEDIUM
Dell Alienware BIOS Authenticated Buffer Overflow via SMI Manipulation
CVSS 4.1
CVE-2022-41202 HIGH
SAP 3D Visual Enterprise Viewer <9 - RCE
CVSS 7.8
CVE-2022-41201 HIGH
SAP 3D Visual Enterprise Viewer <9 - RCE
CVSS 7.8
Details
Vulnerabilities 13,962
Exploit Likelihood High