Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-119

MITRE ↗

Improper Restriction of Operations within the Bounds of a Memory Buffer

1,070
CRITICAL
4,554
HIGH
1,228
MEDIUM
188
LOW
7,064 CVEs · Page 122/142
7.8
CVE-2017-9893

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U

7.8
CVE-2017-9894

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U

7.8
CVE-2017-9895

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "R

7.8
CVE-2017-9896

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "R

7.8
CVE-2017-9897

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U

7.8
CVE-2017-9898

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U

7.8
CVE-2017-9899

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat

7.8
CVE-2017-9900

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat

7.8
CVE-2017-9901

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat

7.8
CVE-2017-9902

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat

7.8
CVE-2017-9903

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat

7.8
CVE-2017-9904

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9905

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9906

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9907

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9908

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9909

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9910

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9911

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9912

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9913

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie

7.8
CVE-2017-9914

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .bie file, related to a "R

7.8
CVE-2017-9915

IrfanView version 4.44 (32bit) with TOOLS plugin 4.50 allows attackers to execute arbitrary code or cause a denial of se

7.8
CVE-2017-9916

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly hav

7.8
CVE-2017-9917

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly hav

7.8
CVE-2017-9918

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-9919

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-9920

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-9921

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-9922

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-9923

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi

7.8
CVE-2017-0340

An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer wi

7.8
CVE-2017-11111

In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer o

7.8
CVE-2017-0243

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic

7.8
CVE-2017-8501

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic

7.8
CVE-2017-8502

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic

7.8
CVE-2017-11190

unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of servi

7.8
CVE-2017-11311

soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow wit

7.8
CVE-2017-11344

Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, R

7.8
CVE-2017-11345

Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT

7.8
CVE-2017-2344

A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow. Malicious exploitation of this

7.8
CVE-2017-9669

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev

7.8
CVE-2017-9671

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev

7.8
CVE-2017-7008

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS

7.8
CVE-2017-7009

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS

7.8
CVE-2017-7014

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graph

7.8
CVE-2017-7015

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Audio" comp

7.8
CVE-2017-7016

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "afclip" com

7.8
CVE-2017-7017

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graph

7.8
CVE-2017-7021

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphi

Frequently Asked Questions

What is CWE-119?

CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-119?

There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.

How can I protect against CWE-119 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.

Detect CWE-119 Vulnerabilities

CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.

Get Started