Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-12-21 CVE-2017-17811 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.
local
low complexity
nasm canonical CWE-119
5.5
2017-12-20 CVE-2017-14385 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in EMC Data Domain and Data Domain OS
An issue was discovered in EMC Data Domain DD OS 5.7 family, versions prior to 5.7.5.6; EMC Data Domain DD OS 6.0 family, versions prior to 6.0.2.9; EMC Data Domain DD OS 6.1 family, versions prior to 6.1.0.21; EMC Data Domain Virtual Edition 2.0 family, all versions; EMC Data Domain Virtual Edition 3.0 family, versions prior to 3.0 SP2 Update 1; and EMC Data Domain Virtual Edition 3.1 family, versions prior to 3.1 Update 2.
network
low complexity
emc CWE-119
7.5
2017-12-20 CVE-2017-16725 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xiongmaitech products
A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface.
network
low complexity
xiongmaitech CWE-119
critical
9.8
2017-12-20 CVE-2017-16717 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in We-Con Levi Studio HMI
A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI.
network
low complexity
we-con CWE-119
8.6
2017-12-20 CVE-2017-4941 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in VMWare Esxi, Fusion and Workstation
VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets.
network
low complexity
vmware CWE-119
8.8
2017-12-19 CVE-2017-17088 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense Syncbreeze
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability.
network
low complexity
flexense CWE-119
7.5
2017-12-19 CVE-2017-15048 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zoom
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
network
low complexity
zoom CWE-119
8.8
2017-12-18 CVE-2017-17740 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
network
low complexity
openldap opensuse oracle mcafee CWE-119
7.5
2017-12-16 CVE-2017-3196 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rawether Project Rawether
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets.
local
low complexity
rawether-project CWE-119
7.8
2017-12-16 CVE-2017-3195 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Commvault Edge 11.0.0
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
network
low complexity
commvault CWE-119
critical
9.8