CWE-119 · 13 888 записей
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE этого класса
10 000 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2020-0796Готовый эксплойт | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Критическая10,0 | KEV | 99,8 % | 12 мар. 2020 г. |
94Срочно | CVE-2010-3765Готовый эксплойт | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Критическая9,8 | KEV | 83,2 % | 27 окт. 2010 г. |
93Срочно | CVE-2014-6332Готовый эксплойт | OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wmicrosoft · windows 7 · CWE-119 | Высокая8,8 | KEV | 95,0 % | 11 нояб. 2014 г. |
91Срочно | CVE-2017-11882Готовый эксплойт | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 microsoft · office · CWE-119 | Высокая7,8 | KEV | 99,9 % | 14 нояб. 2017 г. |
91Срочно | CVE-2009-3459Готовый эксплойт | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exeadobe · acrobat · CWE-119 | Высокая8,8 | KEV | 86,6 % | 13 окт. 2009 г. |
91Срочно | CVE-2015-2426Готовый эксплойт | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, microsoft · windows 10 · CWE-119 | Высокая8,8 | KEV | 86,6 % | 20 июл. 2015 г. |
90Срочно | CVE-2023-4966Готовый эксплойт | Unauthenticated sensitive information disclosurecitrix · netscaler application delivery controller · CWE-119 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
88Срочно | CVE-2008-0015Готовый эксплойт | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequesmicrosoft · windows 2003 server · CWE-119 | Высокая8,8 | KEV | 76,7 % | 7 июл. 2009 г. |
87Срочно | CVE-2021-22991Готовый эксплойт | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,f5 · big-ip access policy manager · CWE-119 | Критическая9,8 | KEV | 61,1 % | 31 мар. 2021 г. |
87Срочно | CVE-2018-7445Готовый эксплойт | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.mikrotik · routeros · CWE-119 | Критическая9,8 | KEV | 60,8 % | 19 мар. 2018 г. |
86Срочно | CVE-2017-6736Готовый эксплойт | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow cisco · ios · CWE-119 | Высокая8,8 | KEV | 70,4 % | 17 июл. 2017 г. |
86Срочно | CVE-2013-1690Готовый эксплойт | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Высокая8,8 | KEV | 69,0 % | 25 июн. 2013 г. |
85Срочно | CVE-2017-11826Готовый эксплойт | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Womicrosoft · office compatibility pack · CWE-119 | Высокая7,8 | KEV | 81,2 % | 13 окт. 2017 г. |
85Срочно | CVE-2020-29557Готовый эксплойт | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.dlink · dir-825 r1 firmware · CWE-119 | Критическая9,8 | KEV | 54,3 % | 29 янв. 2021 г. |
84Срочно | CVE-2011-1889Готовый эксплойт | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execumicrosoft · forefront threat management gateway · CWE-119 | Критическая9,8 | KEV | 49,0 % | 16 июн. 2011 г. |
79На этой неделе | CVE-2017-11774Готовый эксплойт | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsmicrosoft · outlook · CWE-119 | Высокая7,8 | KEV | 59,6 % | 13 окт. 2017 г. |
79На этой неделе | CVE-2017-6737Готовый эксплойт | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to rcisco · ios · CWE-119 | Высокая8,8 | KEV | 45,2 % | 17 июл. 2017 г. |
78На этой неделе | CVE-2016-7193Готовый эксплойт | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibimicrosoft · office · CWE-119 | Высокая7,8 | KEV | 57,6 % | 13 окт. 2016 г. |
78На этой неделе | CVE-2017-0101Готовый эксплойт | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Wmicrosoft · windows 7 · CWE-119 | Высокая7,8 | KEV | 57,5 % | 16 мар. 2017 г. |
78На этой неделе | CVE-2014-3931Готовый эксплойт | fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corrumulti-router looking glass project · multi-router looking glass · CWE-119 | Критическая9,8 | KEV | 29,0 % | 31 мар. 2017 г. |
77На этой неделе | CVE-2023-6549Готовый эксплойт | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denialcitrix · netscaler application delivery controller · CWE-119 | Высокая7,5 | KEV | 57,6 % | 17 янв. 2024 г. |
75На этой неделе | CVE-2025-31200Готовый эксплойт | A memory corruption issue was addressed with improved bounds checking.apple · macos · CWE-119 | Критическая9,8 | KEV | 18,8 % | 16 апр. 2025 г. |
73На этой неделе | CVE-2013-3660Готовый эксплойт | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, microsoft · windows 7 · CWE-119 | Высокая7,8 | KEV | 39,3 % | 24 мая 2013 г. |
73На этой неделе | CVE-2018-0151Готовый эксплойт | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, recisco · ios xe · CWE-119 | Критическая9,8 | KEV | 14,2 % | 28 мар. 2018 г. |
72На этой неделе | CVE-2025-7775Готовый эксплойт | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Критическая9,2 | KEV | 19,6 % | 26 авг. 2025 г. |
- CVE-2020-0796100Срочно
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 190312 мар. 2020 г.
- CVE-2010-376594Срочно
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %mozilla · firefox27 окт. 2010 г.
- CVE-2014-633293Срочно
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 95 %microsoft · windows 711 нояб. 2014 г.
- CVE-2017-1188291Срочно
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %microsoft · office14 нояб. 2017 г.
- CVE-2009-345991Срочно
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exe
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 87 %adobe · acrobat13 окт. 2009 г.
- CVE-2015-242691Срочно
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 87 %microsoft · windows 1020 июл. 2015 г.
- CVE-2023-496690Срочно
Unauthenticated sensitive information disclosure
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller10 окт. 2023 г.
- CVE-2008-001588Срочно
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneReques
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 77 %microsoft · windows 2003 server7 июл. 2009 г.
- CVE-2021-2299187Срочно
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %f5 · big-ip access policy manager31 мар. 2021 г.
- CVE-2018-744587Срочно
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %mikrotik · routeros19 мар. 2018 г.
- CVE-2017-673686Срочно
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 70 %cisco · ios17 июл. 2017 г.
- CVE-2013-169086Срочно
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox25 июн. 2013 г.
- CVE-2017-1182685Срочно
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Wo
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %microsoft · office compatibility pack13 окт. 2017 г.
- CVE-2020-2955785Срочно
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 54 %dlink · dir-825 r1 firmware29 янв. 2021 г.
- CVE-2011-188984Срочно
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 49 %microsoft · forefront threat management gateway16 июн. 2011 г.
- CVE-2017-1177479На этой неделе
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Micros
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 60 %microsoft · outlook13 окт. 2017 г.
- CVE-2017-673779На этой неделе
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to r
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 45 %cisco · ios17 июл. 2017 г.
- CVE-2016-719378На этой неделе
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 58 %microsoft · office13 окт. 2016 г.
- CVE-2017-010178На этой неделе
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, W
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 57 %microsoft · windows 716 мар. 2017 г.
- CVE-2014-393178На этой неделе
fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corru
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 29 %multi-router looking glass project · multi-router looking glass31 мар. 2017 г.
- CVE-2023-654977На этой неделе
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 58 %citrix · netscaler application delivery controller17 янв. 2024 г.
- CVE-2025-3120075На этой неделе
A memory corruption issue was addressed with improved bounds checking.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 19 %apple · macos16 апр. 2025 г.
- CVE-2013-366073На этой неделе
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 39 %microsoft · windows 724 мая 2013 г.
- CVE-2018-015173На этой неделе
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 14 %cisco · ios xe28 мар. 2018 г.
- CVE-2025-777572На этой неделе
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 20 %citrix · netscaler application delivery controller26 авг. 2025 г.