CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An atta
'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->v
An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft Ima
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, S
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer o
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs presen
Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported m
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, wa
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macO
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and F
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be ab
Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon
Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization method
Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packe
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the proc
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdrago
Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrit
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 be
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer
An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Poin
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can re
In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM
Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users
Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Au
Windows DWM Core Library Elevation of Privilege Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). A
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). A
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started