Skip to content
Noroxi

CWE-119 · 13,888 records

Improper Restriction of Operations within the Bounds of a Memory Buffer

CVEs in this class

10,000 records

  • A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    microsoft · windows 10 1903Mar 12, 2020

  • Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    mozilla · firefoxOct 27, 2010

  • OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W

    HighCVSS 8.8KEVWeaponizedEPSS 95%

    microsoft · windows 7Nov 11, 2014

  • Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016

    HighCVSS 7.8KEVWeaponizedEPSS 100%

    microsoft · officeNov 14, 2017

  • Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exe

    HighCVSS 8.8KEVWeaponizedEPSS 87%

    adobe · acrobatOct 13, 2009

  • Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,

    HighCVSS 8.8KEVWeaponizedEPSS 87%

    microsoft · windows 10Jul 20, 2015

  • Unauthenticated sensitive information disclosure

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerOct 10, 2023

  • Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneReques

    HighCVSS 8.8KEVWeaponizedEPSS 77%

    microsoft · windows 2003 serverJul 7, 2009

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,

    CriticalCVSS 9.8KEVWeaponizedEPSS 61%

    f5 · big-ip access policy managerMar 31, 2021

  • A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.

    CriticalCVSS 9.8KEVWeaponizedEPSS 61%

    mikrotik · routerosMar 19, 2018

  • The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow

    HighCVSS 8.8KEVWeaponizedEPSS 70%

    cisco · iosJul 17, 2017

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxJun 25, 2013

  • Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Wo

    HighCVSS 7.8KEVWeaponizedEPSS 81%

    microsoft · office compatibility packOct 13, 2017

  • An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.

    CriticalCVSS 9.8KEVWeaponizedEPSS 54%

    dlink · dir-825 r1 firmwareJan 29, 2021

  • The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execu

    CriticalCVSS 9.8KEVWeaponizedEPSS 49%

    microsoft · forefront threat management gatewayJun 16, 2011

  • CVE-2017-11774
    79This week

    Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Micros

    HighCVSS 7.8KEVWeaponizedEPSS 60%

    microsoft · outlookOct 13, 2017

  • CVE-2017-6737
    79This week

    A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to r

    HighCVSS 8.8KEVWeaponizedEPSS 45%

    cisco · iosJul 17, 2017

  • CVE-2016-7193
    78This week

    Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibi

    HighCVSS 7.8KEVWeaponizedEPSS 58%

    microsoft · officeOct 13, 2016

  • CVE-2017-0101
    78This week

    The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, W

    HighCVSS 7.8KEVWeaponizedEPSS 57%

    microsoft · windows 7Mar 16, 2017

  • CVE-2014-3931
    78This week

    fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corru

    CriticalCVSS 9.8KEVWeaponizedEPSS 29%

    multi-router looking glass project · multi-router looking glassMar 31, 2017

  • CVE-2023-6549
    77This week

    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial

    HighCVSS 7.5KEVWeaponizedEPSS 58%

    citrix · netscaler application delivery controllerJan 17, 2024

  • CVE-2025-31200
    75This week

    A memory corruption issue was addressed with improved bounds checking.

    CriticalCVSS 9.8KEVWeaponizedEPSS 19%

    apple · macosApr 16, 2025

  • CVE-2013-3660
    73This week

    The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,

    HighCVSS 7.8KEVWeaponizedEPSS 39%

    microsoft · windows 7May 24, 2013

  • CVE-2018-0151
    73This week

    A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re

    CriticalCVSS 9.8KEVWeaponizedEPSS 14%

    cisco · ios xeMar 28, 2018

  • CVE-2025-7775
    72This week

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service

    CriticalCVSS 9.2KEVWeaponizedEPSS 20%

    citrix · netscaler application delivery controllerAug 26, 2025

All vulnerability classes