CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Av
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of servi
LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attac
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (hea
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow trigg
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac
Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handl
Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handl
A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a specially crafted file
A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable an attacker using a s
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file t
A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker usi
In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by sp
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified
A buffer overflow vulnerability in all Android releases from CAF using the Linux kernel can potentially occur if an OEM
In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF usi
In TrustZone a buffer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kern
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel d
A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Intel Graph
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Sandbox" co
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServe
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServe
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Multi-Touch
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Multi-Touch
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "IOGraphics"
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServe
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "NVIDIA Grap
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "iBooks" com
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started