CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the fun
A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_004
A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the functi
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function f
A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f
A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If ex
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access po
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSett
Memory corruption while processing IOCTL handler in FastRPC.
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions tha
EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. T
EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv
EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Un
A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerabilit
A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enti
Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP ha
The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_conte
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_ad
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appli
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a g
An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A
An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A speci
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GT
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality
An out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially cr
An out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A spe
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started