CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-o
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory,
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary ch
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19
Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.
FreeTDS through 1.1.11 has a Buffer Overflow.
MiniDLNA has heap-based buffer overflow
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Au
When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to ou
ClamAV before 0.97.7 has WWPack corrupt heap memory
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, a
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overf
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKe
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege an
A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vuln
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK.
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows befor
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, sn
Improper validation of buffer length checks in the lwm2m device management protocol can leads to a buffer overflow in sn
When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker
Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed ev
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs sho
Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed ev
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to che
Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 al
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution.
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution.
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12,
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started