CWE-119 · 13.888 kayıt
Improper Restriction of Operations within the Bounds of a Memory Buffer
Bu sınıftaki CVE’ler
10.000 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2020-0796Silahlaştırılmış | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Kritik10,0 | KEV | %99,8 | 12 Mar 2020 |
94Hemen | CVE-2010-3765Silahlaştırılmış | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Kritik9,8 | KEV | %83,2 | 27 Eki 2010 |
93Hemen | CVE-2014-6332Silahlaştırılmış | OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wmicrosoft · windows 7 · CWE-119 | Yüksek8,8 | KEV | %95,0 | 11 Kas 2014 |
91Hemen | CVE-2017-11882Silahlaştırılmış | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 microsoft · office · CWE-119 | Yüksek7,8 | KEV | %99,9 | 14 Kas 2017 |
91Hemen | CVE-2009-3459Silahlaştırılmış | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exeadobe · acrobat · CWE-119 | Yüksek8,8 | KEV | %86,6 | 13 Eki 2009 |
91Hemen | CVE-2015-2426Silahlaştırılmış | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, microsoft · windows 10 · CWE-119 | Yüksek8,8 | KEV | %86,6 | 20 Tem 2015 |
90Hemen | CVE-2023-4966Silahlaştırılmış | Unauthenticated sensitive information disclosurecitrix · netscaler application delivery controller · CWE-119 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
88Hemen | CVE-2008-0015Silahlaştırılmış | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequesmicrosoft · windows 2003 server · CWE-119 | Yüksek8,8 | KEV | %76,7 | 7 Tem 2009 |
87Hemen | CVE-2021-22991Silahlaştırılmış | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,f5 · big-ip access policy manager · CWE-119 | Kritik9,8 | KEV | %61,1 | 31 Mar 2021 |
87Hemen | CVE-2018-7445Silahlaştırılmış | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.mikrotik · routeros · CWE-119 | Kritik9,8 | KEV | %60,8 | 19 Mar 2018 |
86Hemen | CVE-2017-6736Silahlaştırılmış | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow cisco · ios · CWE-119 | Yüksek8,8 | KEV | %70,4 | 17 Tem 2017 |
86Hemen | CVE-2013-1690Silahlaştırılmış | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Yüksek8,8 | KEV | %69,0 | 25 Haz 2013 |
85Hemen | CVE-2017-11826Silahlaştırılmış | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Womicrosoft · office compatibility pack · CWE-119 | Yüksek7,8 | KEV | %81,2 | 13 Eki 2017 |
85Hemen | CVE-2020-29557Silahlaştırılmış | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.dlink · dir-825 r1 firmware · CWE-119 | Kritik9,8 | KEV | %54,3 | 29 Oca 2021 |
84Hemen | CVE-2011-1889Silahlaştırılmış | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execumicrosoft · forefront threat management gateway · CWE-119 | Kritik9,8 | KEV | %49,0 | 16 Haz 2011 |
79Bu hafta | CVE-2017-11774Silahlaştırılmış | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsmicrosoft · outlook · CWE-119 | Yüksek7,8 | KEV | %59,6 | 13 Eki 2017 |
79Bu hafta | CVE-2017-6737Silahlaştırılmış | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to rcisco · ios · CWE-119 | Yüksek8,8 | KEV | %45,2 | 17 Tem 2017 |
78Bu hafta | CVE-2016-7193Silahlaştırılmış | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibimicrosoft · office · CWE-119 | Yüksek7,8 | KEV | %57,6 | 13 Eki 2016 |
78Bu hafta | CVE-2017-0101Silahlaştırılmış | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Wmicrosoft · windows 7 · CWE-119 | Yüksek7,8 | KEV | %57,5 | 16 Mar 2017 |
78Bu hafta | CVE-2014-3931Silahlaştırılmış | fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corrumulti-router looking glass project · multi-router looking glass · CWE-119 | Kritik9,8 | KEV | %29,0 | 31 Mar 2017 |
77Bu hafta | CVE-2023-6549Silahlaştırılmış | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denialcitrix · netscaler application delivery controller · CWE-119 | Yüksek7,5 | KEV | %57,6 | 17 Oca 2024 |
75Bu hafta | CVE-2025-31200Silahlaştırılmış | A memory corruption issue was addressed with improved bounds checking.apple · macos · CWE-119 | Kritik9,8 | KEV | %18,8 | 16 Nis 2025 |
73Bu hafta | CVE-2013-3660Silahlaştırılmış | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, microsoft · windows 7 · CWE-119 | Yüksek7,8 | KEV | %39,3 | 24 May 2013 |
73Bu hafta | CVE-2018-0151Silahlaştırılmış | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, recisco · ios xe · CWE-119 | Kritik9,8 | KEV | %14,2 | 28 Mar 2018 |
72Bu hafta | CVE-2025-7775Silahlaştırılmış | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Kritik9,2 | KEV | %19,6 | 26 Ağu 2025 |
- CVE-2020-0796100Hemen
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100microsoft · windows 10 190312 Mar 2020
- CVE-2010-376594Hemen
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83mozilla · firefox27 Eki 2010
- CVE-2014-633293Hemen
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %95microsoft · windows 711 Kas 2014
- CVE-2017-1188291Hemen
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100microsoft · office14 Kas 2017
- CVE-2009-345991Hemen
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exe
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87adobe · acrobat13 Eki 2009
- CVE-2015-242691Hemen
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87microsoft · windows 1020 Tem 2015
- CVE-2023-496690Hemen
Unauthenticated sensitive information disclosure
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100citrix · netscaler application delivery controller10 Eki 2023
- CVE-2008-001588Hemen
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneReques
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %77microsoft · windows 2003 server7 Tem 2009
- CVE-2021-2299187Hemen
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61f5 · big-ip access policy manager31 Mar 2021
- CVE-2018-744587Hemen
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61mikrotik · routeros19 Mar 2018
- CVE-2017-673686Hemen
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %70cisco · ios17 Tem 2017
- CVE-2013-169086Hemen
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69mozilla · firefox25 Haz 2013
- CVE-2017-1182685Hemen
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Wo
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81microsoft · office compatibility pack13 Eki 2017
- CVE-2020-2955785Hemen
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %54dlink · dir-825 r1 firmware29 Oca 2021
- CVE-2011-188984Hemen
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execu
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %49microsoft · forefront threat management gateway16 Haz 2011
- CVE-2017-1177479Bu hafta
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Micros
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %60microsoft · outlook13 Eki 2017
- CVE-2017-673779Bu hafta
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to r
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %45cisco · ios17 Tem 2017
- CVE-2016-719378Bu hafta
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibi
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %58microsoft · office13 Eki 2016
- CVE-2017-010178Bu hafta
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, W
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %57microsoft · windows 716 Mar 2017
- CVE-2014-393178Bu hafta
fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corru
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %29multi-router looking glass project · multi-router looking glass31 Mar 2017
- CVE-2023-654977Bu hafta
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %58citrix · netscaler application delivery controller17 Oca 2024
- CVE-2025-3120075Bu hafta
A memory corruption issue was addressed with improved bounds checking.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %19apple · macos16 Nis 2025
- CVE-2013-366073Bu hafta
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %39microsoft · windows 724 May 2013
- CVE-2018-015173Bu hafta
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %14cisco · ios xe28 Mar 2018
- CVE-2025-777572Bu hafta
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
KritikCVSS 9,2KEVSilahlaştırılmışEPSS %20citrix · netscaler application delivery controller26 Ağu 2025