CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRD
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use t
There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.
libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. Thi
libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.c
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially caus
OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows
A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immed
A vulnerability has been found in Anvsoft PDFMate PDF Converter Pro 1.7.5.0 and classified as critical. The manipulation
A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the func
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the fun
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a
Improper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause
Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of
Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication
A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This ca
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the
A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of th
A Denial of Service vulnerability exists in Binaryen 103. The program terminates with signal SIGKILL.
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulner
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This
In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an invalid memory access. This could lead to l
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().
GPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerab
Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.
There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object
Microsoft Excel Information Disclosure Vulnerability
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to inval
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM
Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that coul
radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a sta
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a sta
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a sta
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input
Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products be
An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started