Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-1000880 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file.
6.5
2018-12-20 CVE-2018-11986 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in TX and RX FIFOs of microcontroller in camera subsystem used to exchange commands and messages between Micro FW and CPP driver.
local
low complexity
google CWE-119
7.8
2018-12-20 CVE-2018-11961 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GNSS configurations.
local
low complexity
google CWE-119
7.8
2018-12-20 CVE-2018-5200 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pandora Kmplayer
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability.
local
low complexity
pandora CWE-119
7.8
2018-12-20 CVE-2018-1771 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Domino and Notes
IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe.
local
low complexity
ibm CWE-119
7.8
2018-12-20 CVE-2018-20304 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libexcel Project Libexcel 0.01
wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long second argument.
network
low complexity
libexcel-project CWE-119
6.5
2018-12-19 CVE-2018-20299 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bosch products
An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4.
network
low complexity
bosch CWE-119
critical
9.8
2018-12-18 CVE-2018-20213 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libexcel Project Libexcel 0.01
wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name.
network
low complexity
libexcel-project CWE-119
7.5
2018-12-17 CVE-2018-19036 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bosch products
An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher.
network
low complexity
bosch CWE-119
critical
9.8
2018-12-17 CVE-2018-14856 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Samsung Galaxy S6 Firmware G920Fxxu5Eqh7
Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to perform invalid memory accesses.
low complexity
samsung CWE-119
6.3