Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-06-06 CVE-2017-18154 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-119
7.8
2018-05-31 CVE-2016-10523 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mqtt-Packet Project Mqtt-Packet 4.0.0
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very little bandwidth.
network
low complexity
mqtt-packet-project CWE-119
7.5
2018-05-31 CVE-2016-10518 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in WS Project WS
A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame.
network
low complexity
ws-project CWE-119
7.5
2018-05-31 CVE-2018-11596 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Espruino
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because a check for '\0' is made for the wrong array element in jsvar.c.
local
low complexity
espruino CWE-119
5.5
2018-05-31 CVE-2018-11595 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Espruino
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow during syntax parsing, because strncat is misused.
local
low complexity
espruino CWE-119
7.8
2018-05-31 CVE-2018-11594 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Espruino
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing of "VOID" tokens in jsparse.c.
local
low complexity
espruino CWE-119
5.5
2018-05-31 CVE-2018-11578 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Miniupnp Project Ngiflib 0.4
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.
network
low complexity
miniupnp-project CWE-119
6.5
2018-05-26 CVE-2018-11498 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Lizard Project Lizard and LZ5
In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h).
local
low complexity
lizard-project CWE-119
7.8
2018-05-25 CVE-2018-1565 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner.
local
low complexity
ibm CWE-119
7.8
2018-05-25 CVE-2018-1544 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner.
local
low complexity
ibm CWE-119
7.8