CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
IrfanView version 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact v
IrfanView 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a cr
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component.
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "IOFireWireFam
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS befor
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. iCloud bef
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component.
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component.
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component.
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component.
A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to
elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocat
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_ve
Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) an
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations fie
drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection
Special crafted InPage document leads to arbitrary code execution in InPage reader.
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote at
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows re
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" compo
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Remote Mana
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "fsck_msdos"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" co
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Open Script
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HFS" compon
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork"
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started