CWE-119
MITRE ↗Improper Restriction of Operations within the Bounds of a Memory Buffer
When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdrago
Buffer overwrite can happen in WLAN due to lack of validation of the input length in Snapdragon Mobile in version SD 845
Buffer overflow can happen in WLAN function due to lack of validation of the input length in Snapdragon Mobile in versio
Buffer overflow can happen in WLAN module due to lack of validation of the input length in Snapdragon Mobile in version
Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow i
Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation
Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile i
Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in ver
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version
When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrit
Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835,
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Sna
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memo
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to caus
DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem
Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with a
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a partition n
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a po
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a po
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overfl
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a memory corr
Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ f
While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66
In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor
Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile,
Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo
Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can
A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility o
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buff
Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain th
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Syste
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addr
In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote den
The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, rem
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
Frequently Asked Questions
What is CWE-119?
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-119?
There are 14,545 CVE records associated with CWE-119 in our database. Of these, 1070 are critical severity, 4554 are high severity, and 1228 are medium severity.
How can I protect against CWE-119 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-119 using AI-powered security agents.
Detect CWE-119 Vulnerabilities
CyberStrike's AI agents automatically detect improper restriction of operations within the bounds of a memory buffer vulnerabilities across your infrastructure.
Get Started