VYPR

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

ClassStableLikelihood: High

Description

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (14,335)

page 27 of 717
  • CVE-2018-4332CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

  • CVE-2018-4331CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.04

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

  • CVE-2018-4291CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4288CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4287CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4286CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4268CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2018-4259CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

  • CVE-2014-9189CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.05

    Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial…

  • CVE-2014-9187CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly…

  • CVE-2019-9895CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.02

    In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

  • CVE-2018-18493CriFeb 28, 2019
    risk 0.64cvss 9.8epss 0.04

    A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4,…

  • CVE-2018-12407CriFeb 28, 2019
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

  • CVE-2018-12405CriFeb 28, 2019
    risk 0.64cvss 9.8epss 0.03

    Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This…

  • CVE-2018-12390CriFeb 28, 2019
    risk 0.64cvss 9.8epss 0.03

    Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This…

  • CVE-2019-8996CriFeb 21, 2019
    risk 0.64cvss 9.8epss 0.02

    In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow.

  • CVE-2018-12547CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.03

    In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user…

  • CVE-2018-18502CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects…

  • CVE-2018-18501CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.03

    Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This…

  • CVE-2018-12548CriJan 31, 2019
    risk 0.64cvss 9.8epss 0.01

    In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.