CWE-119 · 13,888 records
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2020-0796Weaponized | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Critical10.0 | KEV | 99.8% | Mar 12, 2020 |
94Now | CVE-2010-3765Weaponized | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Critical9.8 | KEV | 83.2% | Oct 27, 2010 |
93Now | CVE-2014-6332Weaponized | OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wmicrosoft · windows 7 · CWE-119 | High8.8 | KEV | 95.0% | Nov 11, 2014 |
91Now | CVE-2017-11882Weaponized | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 microsoft · office · CWE-119 | High7.8 | KEV | 99.9% | Nov 14, 2017 |
91Now | CVE-2009-3459Weaponized | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exeadobe · acrobat · CWE-119 | High8.8 | KEV | 86.6% | Oct 13, 2009 |
91Now | CVE-2015-2426Weaponized | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, microsoft · windows 10 · CWE-119 | High8.8 | KEV | 86.6% | Jul 20, 2015 |
90Now | CVE-2023-4966Weaponized | Unauthenticated sensitive information disclosurecitrix · netscaler application delivery controller · CWE-119 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
88Now | CVE-2008-0015Weaponized | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequesmicrosoft · windows 2003 server · CWE-119 | High8.8 | KEV | 76.7% | Jul 7, 2009 |
87Now | CVE-2021-22991Weaponized | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,f5 · big-ip access policy manager · CWE-119 | Critical9.8 | KEV | 61.1% | Mar 31, 2021 |
87Now | CVE-2018-7445Weaponized | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.mikrotik · routeros · CWE-119 | Critical9.8 | KEV | 60.8% | Mar 19, 2018 |
86Now | CVE-2017-6736Weaponized | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow cisco · ios · CWE-119 | High8.8 | KEV | 70.4% | Jul 17, 2017 |
86Now | CVE-2013-1690Weaponized | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | High8.8 | KEV | 69.0% | Jun 25, 2013 |
85Now | CVE-2017-11826Weaponized | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Womicrosoft · office compatibility pack · CWE-119 | High7.8 | KEV | 81.2% | Oct 13, 2017 |
85Now | CVE-2020-29557Weaponized | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.dlink · dir-825 r1 firmware · CWE-119 | Critical9.8 | KEV | 54.3% | Jan 29, 2021 |
84Now | CVE-2011-1889Weaponized | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execumicrosoft · forefront threat management gateway · CWE-119 | Critical9.8 | KEV | 49.0% | Jun 16, 2011 |
79This week | CVE-2017-11774Weaponized | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsmicrosoft · outlook · CWE-119 | High7.8 | KEV | 59.6% | Oct 13, 2017 |
79This week | CVE-2017-6737Weaponized | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to rcisco · ios · CWE-119 | High8.8 | KEV | 45.2% | Jul 17, 2017 |
78This week | CVE-2016-7193Weaponized | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibimicrosoft · office · CWE-119 | High7.8 | KEV | 57.6% | Oct 13, 2016 |
78This week | CVE-2017-0101Weaponized | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Wmicrosoft · windows 7 · CWE-119 | High7.8 | KEV | 57.5% | Mar 16, 2017 |
78This week | CVE-2014-3931Weaponized | fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corrumulti-router looking glass project · multi-router looking glass · CWE-119 | Critical9.8 | KEV | 29.0% | Mar 31, 2017 |
77This week | CVE-2023-6549Weaponized | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denialcitrix · netscaler application delivery controller · CWE-119 | High7.5 | KEV | 57.6% | Jan 17, 2024 |
75This week | CVE-2025-31200Weaponized | A memory corruption issue was addressed with improved bounds checking.apple · macos · CWE-119 | Critical9.8 | KEV | 18.8% | Apr 16, 2025 |
73This week | CVE-2013-3660Weaponized | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, microsoft · windows 7 · CWE-119 | High7.8 | KEV | 39.3% | May 24, 2013 |
73This week | CVE-2018-0151Weaponized | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, recisco · ios xe · CWE-119 | Critical9.8 | KEV | 14.2% | Mar 28, 2018 |
72This week | CVE-2025-7775Weaponized | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Critical9.2 | KEV | 19.6% | Aug 26, 2025 |
- CVE-2020-0796100Now
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
CriticalCVSS 10.0KEVWeaponizedEPSS 100%microsoft · windows 10 1903Mar 12, 2020
- CVE-2010-376594Now
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
CriticalCVSS 9.8KEVWeaponizedEPSS 83%mozilla · firefoxOct 27, 2010
- CVE-2014-633293Now
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W
HighCVSS 8.8KEVWeaponizedEPSS 95%microsoft · windows 7Nov 11, 2014
- CVE-2017-1188291Now
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016
HighCVSS 7.8KEVWeaponizedEPSS 100%microsoft · officeNov 14, 2017
- CVE-2009-345991Now
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exe
HighCVSS 8.8KEVWeaponizedEPSS 87%adobe · acrobatOct 13, 2009
- CVE-2015-242691Now
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
HighCVSS 8.8KEVWeaponizedEPSS 87%microsoft · windows 10Jul 20, 2015
- CVE-2023-496690Now
Unauthenticated sensitive information disclosure
HighCVSS 7.5KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerOct 10, 2023
- CVE-2008-001588Now
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneReques
HighCVSS 8.8KEVWeaponizedEPSS 77%microsoft · windows 2003 serverJul 7, 2009
- CVE-2021-2299187Now
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,
CriticalCVSS 9.8KEVWeaponizedEPSS 61%f5 · big-ip access policy managerMar 31, 2021
- CVE-2018-744587Now
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
CriticalCVSS 9.8KEVWeaponizedEPSS 61%mikrotik · routerosMar 19, 2018
- CVE-2017-673686Now
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow
HighCVSS 8.8KEVWeaponizedEPSS 70%cisco · iosJul 17, 2017
- CVE-2013-169086Now
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxJun 25, 2013
- CVE-2017-1182685Now
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Wo
HighCVSS 7.8KEVWeaponizedEPSS 81%microsoft · office compatibility packOct 13, 2017
- CVE-2020-2955785Now
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.
CriticalCVSS 9.8KEVWeaponizedEPSS 54%dlink · dir-825 r1 firmwareJan 29, 2021
- CVE-2011-188984Now
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execu
CriticalCVSS 9.8KEVWeaponizedEPSS 49%microsoft · forefront threat management gatewayJun 16, 2011
- CVE-2017-1177479This week
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Micros
HighCVSS 7.8KEVWeaponizedEPSS 60%microsoft · outlookOct 13, 2017
- CVE-2017-673779This week
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to r
HighCVSS 8.8KEVWeaponizedEPSS 45%cisco · iosJul 17, 2017
- CVE-2016-719378This week
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibi
HighCVSS 7.8KEVWeaponizedEPSS 58%microsoft · officeOct 13, 2016
- CVE-2017-010178This week
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, W
HighCVSS 7.8KEVWeaponizedEPSS 57%microsoft · windows 7Mar 16, 2017
- CVE-2014-393178This week
fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corru
CriticalCVSS 9.8KEVWeaponizedEPSS 29%multi-router looking glass project · multi-router looking glassMar 31, 2017
- CVE-2023-654977This week
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial
HighCVSS 7.5KEVWeaponizedEPSS 58%citrix · netscaler application delivery controllerJan 17, 2024
- CVE-2025-3120075This week
A memory corruption issue was addressed with improved bounds checking.
CriticalCVSS 9.8KEVWeaponizedEPSS 19%apple · macosApr 16, 2025
- CVE-2013-366073This week
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
HighCVSS 7.8KEVWeaponizedEPSS 39%microsoft · windows 7May 24, 2013
- CVE-2018-015173This week
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re
CriticalCVSS 9.8KEVWeaponizedEPSS 14%cisco · ios xeMar 28, 2018
- CVE-2025-777572This week
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
CriticalCVSS 9.2KEVWeaponizedEPSS 20%citrix · netscaler application delivery controllerAug 26, 2025