CWE-119— Buffer Operations Within Bounds (Buffer Overflow)
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.— MITRE CWE catalog
14,450 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-119page 2 of 289
- CVE-2016-1646CRITICALCVSS 8.8EG 9.0⚠ KEV2016-03-29
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds …
- CVE-2015-2502CRITICALCVSS 8.8EG 9.0⚠ KEV2015-08-19
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2…
- CVE-2015-2426CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-20
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1…
- CVE-2015-2425CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability th…
- CVE-2015-2424CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corrupti…
- CVE-2015-2419CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
- CVE-2015-2360CRITICALCVSS 8.8EG 9.0⚠ KEV2015-06-10
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8…
- CVE-2014-8439CRITICALCVSS 8.8EG 9.0⚠ KEV2014-11-25
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 all…
- CVE-2014-6332CRITICALCVSS 8.8EG 9.0⚠ KEV2014-11-11
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to…
- CVE-2013-3918CRITICALCVSS 8.8EG 9.0⚠ KEV2013-11-12
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server…
- CVE-2013-1690CRITICALCVSS 8.8EG 9.0⚠ KEV2013-06-26
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attacke…
- CVE-2012-1889CRITICALCVSS 8.8EG 9.0⚠ KEV2012-06-13
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
- CVE-2011-0611CRITICALCVSS 8.8EG 9.0⚠ KEV2011-04-13
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through …
- CVE-2009-3953CRITICALCVSS 8.8EG 9.0⚠ KEV2010-01-13
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODPr…
- CVE-2009-3459CRITICALCVSS 8.8EG 9.0⚠ KEV2009-10-13
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wil…
- CVE-2008-0015CRITICALCVSS 8.8EG 9.0⚠ KEV2009-07-07
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Ser…
- CVE-2023-33106CRITICALCVSS 8.4EG 9.0⚠ KEV2023-12-05
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- CVE-2013-2597CRITICALCVSS 8.4EG 9.0⚠ KEV2014-08-31
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allo…
- CVE-2023-6549CRITICALCVSS 8.2EG 9.0⚠ KEV2024-01-17
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
- CVE-2015-2546CRITICALCVSS 8.2EG 9.0⚠ KEV2015-09-09
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privilege…
- CVE-2026-88772CRITICALCVSS 8.1EG 9.0⚠ KEV2026-09-27
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64…
- CVE-2012-0754CRITICALCVSS 8.1EG 9.0⚠ KEV2012-02-16
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause …
- CVE-2018-0175CRITICALCVSS 8.0EG 9.0⚠ KEV2018-03-28
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) …
- CVE-2026-20700CRITICALCVSS 7.8EG 9.0⚠ KEV2026-02-11
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to exec…
- CVE-2024-35250CRITICALCVSS 7.8EG 9.0⚠ KEV2024-06-11
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- CVE-2023-36033CRITICALCVSS 7.8EG 9.0⚠ KEV2023-11-14
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2022-22706CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-03
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
- CVE-2021-38646CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
- CVE-2021-33771CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2021-31979CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2020-9907CRITICALCVSS 7.8EG 9.0⚠ KEV2020-10-16
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
- CVE-2020-1380CRITICALCVSS 7.8EG 9.0⚠ KEV2020-08-17
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the con…
- CVE-2020-3837CRITICALCVSS 7.8EG 9.0⚠ KEV2020-02-27
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kerne…
- CVE-2019-1214CRITICALCVSS 7.8EG 9.0⚠ KEV2019-09-11
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
- CVE-2018-4344CRITICALCVSS 7.8EG 9.0⚠ KEV2019-04-03
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
- CVE-2017-11882CRITICALCVSS 7.8EG 9.0⚠ KEV2017-11-15
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly h…
- CVE-2017-11826CRITICALCVSS 7.8EG 9.0⚠ KEV2017-10-13
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow…
- CVE-2017-11774CRITICALCVSS 7.8EG 9.0⚠ KEV2017-10-13
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
- CVE-2017-1000253CRITICALCVSS 7.8EG 9.0⚠ KEV2017-10-05
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b…
- CVE-2017-8540CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-26
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 15…
- CVE-2017-0101CRITICALCVSS 7.8EG 9.0⚠ KEV2017-03-17
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server…
- CVE-2017-0005CRITICALCVSS 7.8EG 9.0⚠ KEV2017-03-17
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to …
- CVE-2016-7193CRITICALCVSS 7.8EG 9.0⚠ KEV2016-10-14
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation…
- CVE-2015-1642CRITICALCVSS 7.8EG 9.0⚠ KEV2015-08-15
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
- CVE-2014-4404CRITICALCVSS 7.8EG 9.0⚠ KEV2014-09-18
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
- CVE-2014-1761CRITICALCVSS 7.8EG 9.0⚠ KEV2014-03-25
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and …
- CVE-2013-1331CRITICALCVSS 7.8EG 9.0⚠ KEV2013-06-12
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerabi…
- CVE-2013-3660CRITICALCVSS 7.8EG 9.0⚠ KEV2013-05-24
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server…
- CVE-2010-4398CRITICALCVSS 7.8EG 9.0⚠ KEV2010-12-06
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local use…
- CVE-2010-3333CRITICALCVSS 7.8EG 9.0⚠ KEV2010-11-10
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitra…
Map vulnerabilities like CWE-119 to your infrastructure
EchelonGraph correlates every CVE — across CWE-119 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →