VYPR

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

ClassStableLikelihood: High

Description

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (14,335)

page 28 of 717
  • CVE-2018-4281CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.01

    In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation.

  • CVE-2018-4258CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.01

    In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.

  • CVE-2018-4257CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.01

    In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.

  • CVE-2018-4189CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.02

    In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling.

  • CVE-2018-4147CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.01

    In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.

  • CVE-2018-0668CriJan 9, 2019
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may result in executing arbtrary code via unspecified vectors.

  • CVE-2018-0651CriJan 9, 2019
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers…

  • CVE-2018-17161CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.03

    In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a stack buffer overflow. It is…

  • CVE-2018-19873CriDec 26, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

  • CVE-2018-20248CriDec 24, 2018
    risk 0.64cvss 9.8epss 0.01

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may…

  • CVE-2018-19240CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

  • CVE-2018-20299CriDec 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there…

  • CVE-2018-19036CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface.

  • CVE-2018-11905CriDec 7, 2018
    risk 0.64cvss 9.8epss 0.01

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in WLAN function due to lack of input validation in values received from firmware.

  • CVE-2018-14749CriNov 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.

  • CVE-2018-19528CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.

  • CVE-2009-5153CriNov 21, 2018
    risk 0.64cvss 9.8epss 0.05

    In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.

  • CVE-2018-18861CriNov 20, 2018
    risk 0.64cvss 9.8epss 0.04

    Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.

  • CVE-2018-18439CriNov 20, 2018
    risk 0.64cvss 9.8epss 0.02

    DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.

  • CVE-2018-0684CriNov 15, 2018
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.