CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch M
A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (I
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of pack
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itse
partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validat
partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient vali
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or c
An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Li
A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software co
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence o
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessib
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affect
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corrup
Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume t
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed eviden
Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume t
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. Th
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a po
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely l
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corrup
Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume t
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. T
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corrup
Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume t
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corrup
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started