CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacke
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 1
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 1
A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233
On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query strin
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, whe
The Gumstix Overo SBC on the VSKS board through 2022-08-09, as used on the Orlan-10 and other platforms, allows unrestri
Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potent
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration fil
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 a
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec.
Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local au
Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged
Improper buffer restrictions in BIOS firmware for some Intel(R) NUC M15 Laptop Kits before version BCTGL357.0074 may all
A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffe
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i
Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/A
The dag-pb codec can panic when decoding invalid blocks.
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled
A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The m
A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stre
A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_
A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decod
Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function
A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function
A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::Write
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown funct
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the fun
A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryBy
A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can sub
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer fr
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c fi
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular use
Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readu
Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation o
Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Co
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, mac
In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to lo
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the O
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started