İçeriğe atla
Noroxi

CWE-119 · 13.888 kayıt

Improper Restriction of Operations within the Bounds of a Memory Buffer

Bu sınıftaki CVE’ler

10.000 kayıt

  • A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    microsoft · windows 10 190312 Mar 2020

  • Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83

    mozilla · firefox27 Eki 2010

  • OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %95

    microsoft · windows 711 Kas 2014

  • Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    microsoft · office14 Kas 2017

  • Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to exe

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87

    adobe · acrobat13 Eki 2009

  • Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87

    microsoft · windows 1020 Tem 2015

  • Unauthenticated sensitive information disclosure

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    citrix · netscaler application delivery controller10 Eki 2023

  • Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneReques

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %77

    microsoft · windows 2003 server7 Tem 2009

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61

    f5 · big-ip access policy manager31 Mar 2021

  • A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61

    mikrotik · routeros19 Mar 2018

  • The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %70

    cisco · ios17 Tem 2017

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox25 Haz 2013

  • Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Wo

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81

    microsoft · office compatibility pack13 Eki 2017

  • An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %54

    dlink · dir-825 r1 firmware29 Oca 2021

  • The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execu

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %49

    microsoft · forefront threat management gateway16 Haz 2011

  • CVE-2017-11774
    79Bu hafta

    Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Micros

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %60

    microsoft · outlook13 Eki 2017

  • CVE-2017-6737
    79Bu hafta

    A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to r

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %45

    cisco · ios17 Tem 2017

  • CVE-2016-7193
    78Bu hafta

    Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibi

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %58

    microsoft · office13 Eki 2016

  • CVE-2017-0101
    78Bu hafta

    The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, W

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %57

    microsoft · windows 716 Mar 2017

  • CVE-2014-3931
    78Bu hafta

    fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corru

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %29

    multi-router looking glass project · multi-router looking glass31 Mar 2017

  • CVE-2023-6549
    77Bu hafta

    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %58

    citrix · netscaler application delivery controller17 Oca 2024

  • CVE-2025-31200
    75Bu hafta

    A memory corruption issue was addressed with improved bounds checking.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %19

    apple · macos16 Nis 2025

  • CVE-2013-3660
    73Bu hafta

    The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %39

    microsoft · windows 724 May 2013

  • CVE-2018-0151
    73Bu hafta

    A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %14

    cisco · ios xe28 Mar 2018

  • CVE-2025-7775
    72Bu hafta

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service

    KritikCVSS 9,2KEVSilahlaştırılmışEPSS %20

    citrix · netscaler application delivery controller26 Ağu 2025

Tüm zafiyet sınıfları