CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Description
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9
CVEs mapped to this weakness (14,335)
page 25 of 717| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13452 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. | ||
| CVE-2019-13451 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. | ||
| CVE-2019-15548 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. | ||
| CVE-2018-20995 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled. | ||
| CVE-2019-14300 | Cri | 0.64 | 9.8 | 0.03 | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration… | ||
| CVE-2019-14308 | Cri | 0.64 | 9.8 | 0.03 | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is… | ||
| CVE-2019-8006 | Cri | 0.64 | 9.8 | 0.04 | Aug 20, 2019 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful… | ||
| CVE-2019-14708 | Cri | 0.64 | 9.8 | 0.04 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account. | ||
| CVE-2019-14698 | Cri | 0.64 | 9.8 | 0.04 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buffer overflow in the param parameter leads to remote code execution in the context of the nobody account. | ||
| CVE-2019-2327 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2019 | Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206,… | ||
| CVE-2019-2322 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2019 | Buffer overflow can occur when playing specific clip which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in… | ||
| CVE-2019-2254 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2019 | Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206,… | ||
| CVE-2019-2269 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2019 | Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9650,… | ||
| CVE-2019-6824 | Cri | 0.64 | 9.8 | 0.04 | Jul 15, 2019 | A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0. | ||
| CVE-2019-1010022 | Cri | 0.64 | 9.8 | 0.03 | Jul 15, 2019 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream… | ||
| CVE-2017-13719 | Cri | 0.64 | 9.8 | 0.03 | Jul 3, 2019 | The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management interface that is provided by the application. This HTTP API receives the… | ||
| CVE-2019-7165 | Cri | 0.64 | 9.8 | 0.04 | Jul 3, 2019 | A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. | ||
| CVE-2018-11425 | Cri | 0.64 | 9.8 | 0.01 | Jul 3, 2019 | Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424. | ||
| CVE-2017-8410 | Cri | 0.64 | 9.8 | 0.06 | Jul 2, 2019 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operation at address 0x00011E34 with the value sent in the… | ||
| CVE-2018-15519 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2019 | Various Lexmark devices have a Buffer Overflow (issue 1 of 2). |
- risk 0.64cvss 9.8epss 0.02
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
- risk 0.64cvss 9.8epss 0.02
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.
- risk 0.64cvss 9.8epss 0.03
Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration…
- risk 0.64cvss 9.8epss 0.03
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is…
- risk 0.64cvss 9.8epss 0.04
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful…
- risk 0.64cvss 9.8epss 0.04
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buffer overflow in the param parameter leads to remote code execution in the context of the nobody account.
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206,…
- risk 0.64cvss 9.8epss 0.01
Buffer overflow can occur when playing specific clip which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in…
- risk 0.64cvss 9.8epss 0.01
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206,…
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9650,…
- risk 0.64cvss 9.8epss 0.04
A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.
- risk 0.64cvss 9.8epss 0.03
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream…
- risk 0.64cvss 9.8epss 0.03
The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management interface that is provided by the application. This HTTP API receives the…
- risk 0.64cvss 9.8epss 0.04
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424.
- risk 0.64cvss 9.8epss 0.06
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operation at address 0x00011E34 with the value sent in the…
- risk 0.64cvss 9.8epss 0.01
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).