CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS)
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data
Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) befor
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to caus
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attacke
All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, le
Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attacker
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related t
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0.
Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to ca
JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by te
magick/memory.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) v
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause
A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will ca
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (mem
The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Windows 10, 1511, and 16
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerabilit
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or ca
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or ca
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation viol
magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds acc
GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EO
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script
An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabV
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with s
A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handlin
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerabilit
A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines rende
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerabilit
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started