CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and
A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5
Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escap
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missin
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a variable is uninitialized in a TrustZo
In all Qualcomm products with Android releases from CAF using the Linux kernel, a Sample App failed to check a length po
In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface w
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths is missing
In all Qualcomm products with Android releases from CAF using the Linux kernel, a string can fail to be null-terminated
In all Qualcomm products with Android releases from CAF using the Linux kernel, a memory buffer fails to be freed after
In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a m
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the proc
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists w
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists w
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GERAN where a
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow v
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists
In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello r
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel mem
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow v
A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Op
Buffer overflow in xymon 4.3.17-1.
Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact vi
Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of ser
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers h
An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess v
Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary c
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started