Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-06-20 CVE-2018-11701 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Faststone Image Viewer 6.2
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe.
local
low complexity
faststone CWE-119
7.8
2018-06-18 CVE-2018-10621 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Delta Industrial Automation Dopsoft
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten.
network
low complexity
deltaww CWE-119
critical
9.8
2018-06-18 CVE-2018-10617 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Delta Industrial Automation Dopsoft
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten.
network
low complexity
deltaww CWE-119
critical
9.8
2018-06-17 CVE-2018-12326 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Redislabs Redis
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line.
local
low complexity
redislabs CWE-119
8.4
2018-06-15 CVE-2018-5863 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-119
7.8
2018-06-15 CVE-2018-12422 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Gnome Evolution
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function.
network
low complexity
gnome CWE-119
critical
9.8
2018-06-13 CVE-2018-7167 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nodejs Node.Js
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service.
network
low complexity
nodejs CWE-119
7.5
2018-06-12 CVE-2018-5843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which can lead to a buffer overwrite of the fixed size chain_rssi_result structure.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-5842 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-3581 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overwrite can occur if the vdev_id received from firmware is larger than max_bssid.
local
low complexity
google CWE-119
7.8