Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-09-04 CVE-2018-16420 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.6
2018-09-04 CVE-2018-16419 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.6
2018-09-04 CVE-2018-16418 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.6
2018-09-03 CVE-2018-16393 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.8
2018-09-03 CVE-2018-16392 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.8
2018-09-03 CVE-2018-16391 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opensc Project Opensc
Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
low complexity
opensc-project CWE-119
6.8
2018-09-02 CVE-2018-16333 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tendacn products
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices.
network
low complexity
tendacn CWE-119
7.5
2018-09-01 CVE-2018-16302 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mc1Soft Zip-N-Go
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
local
low complexity
mc1soft CWE-119
7.8
2018-08-29 CVE-2018-12811 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Photoshop CC
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability.
network
low complexity
adobe CWE-119
critical
9.8
2018-08-29 CVE-2018-12810 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe Photoshop CC
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability.
network
low complexity
adobe CWE-119
critical
9.8