CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory ad
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an
Adobe Illustrator versions 24.1.2 and earlier have a buffer errors vulnerability. Successful exploitation could lead to
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incor
Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdrago
Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in S
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_ca
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An at
u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snap
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could al
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary US
In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer
A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solu
On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stor
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Data outside of the rkp log buffer bo
A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Contro
An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting
An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query
An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong t
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a lo
A flaw exists in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) due to improper validation of user-supplied data whe
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding speci
Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers
Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Softw
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started