CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a cra
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a cr
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .epub file, re
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, re
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, rel
XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a cr
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffe
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function,
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started