Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2018-01-24 CVE-2018-6192 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
local
low complexity
artifex debian CWE-119
5.5
2018-01-24 CVE-2017-13696 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense products
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component.
network
low complexity
flexense CWE-119
critical
9.8
2018-01-23 CVE-2018-5359 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense Sysgauge 3.6.18
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow.
network
high complexity
flexense CWE-119
8.1
2018-01-23 CVE-2016-5345 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted application, aka Android internal bug 32639452 and Qualcomm internal bug CR1079713.
local
high complexity
google CWE-119
7.0
2018-01-22 CVE-2017-17858 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Mupdf 1.12.0
Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted.
local
low complexity
artifex CWE-119
7.8
2018-01-22 CVE-2017-18047 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Labf Nfsaxe 3.7
Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.
network
low complexity
labf CWE-119
critical
9.8
2018-01-21 CVE-2017-18046 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dasannetworks H640X Firmware 12.0201121/2.77P11124/3.03P21146
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi).
network
low complexity
dasannetworks CWE-119
critical
9.8
2018-01-18 CVE-2018-5766 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libav
In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c.
network
low complexity
libav CWE-119
8.8
2018-01-17 CVE-2018-5195 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hancom Thinkfree Office NEO 9.6.1.4902/9.6.1.5183
Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when performing the hyperlink Attributes in document.
network
low complexity
hancom CWE-119
critical
9.8
2018-01-16 CVE-2017-11072 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header fields with partition entries greater than 16384 buffer overflow occurs.
local
low complexity
google CWE-119
7.8