Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-10-03 CVE-2018-17540 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.
network
low complexity
strongswan debian canonical CWE-119
7.5
2018-10-02 CVE-2017-7908 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior.
network
low complexity
gigasoft ge CWE-119
7.6
2018-10-01 CVE-2018-3984 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Atlantiswordprocessor Atlantis Word Processor 3.0.2.3/3.0.2.5
An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5.
local
low complexity
atlantiswordprocessor CWE-119
7.8
2018-10-01 CVE-2018-14802 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fujielectric Frenic Loader 3.3 Firmware 7.3.4.1A
Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace.
network
low complexity
fujielectric CWE-119
critical
9.8
2018-10-01 CVE-2018-14794 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fujielectric Alpha5 Smart Loader Firmware
Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior.
network
low complexity
fujielectric CWE-119
critical
9.8
2018-10-01 CVE-2018-17847 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.
network
low complexity
golang fedoraproject CWE-119
7.5
2018-09-26 CVE-2018-16713 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iobit Advanced Systemcare 1.2.0.5
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content.
network
low complexity
iobit CWE-119
6.5
2018-09-26 CVE-2018-16711 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iobit Advanced Systemcare 1.2.0.5
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content.
network
low complexity
iobit CWE-119
8.8
2018-09-23 CVE-2018-17407 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.
local
low complexity
tug canonical debian CWE-119
7.8
2018-09-23 CVE-2018-17359 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.31.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.
local
low complexity
gnu CWE-119
5.5