CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "R
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "R
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "U
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Dat
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecifie
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .bie file, related to a "R
IrfanView version 4.44 (32bit) with TOOLS plugin 4.50 allows attackers to execute arbitrary code or cause a denial of se
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly hav
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly hav
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbi
An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer wi
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer o
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of servi
soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow wit
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, R
Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT
A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow. Malicious exploitation of this
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graph
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Audio" comp
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "afclip" com
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graph
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphi
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started