Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-13784 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-119
8.8
2017-11-13 CVE-2017-13783 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-119
8.8
2017-11-12 CVE-2017-16796 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Swftools 0.9.2
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application crash) or possibly have unspecified other impact via vectors involving an IDAT tag in a crafted PNG file.
local
low complexity
swftools CWE-119
7.8
2017-11-12 CVE-2017-16793 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Swftools 0.9.2
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.
local
low complexity
swftools CWE-119
7.8
2017-11-10 CVE-2017-12969 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Avaya IP Office Contact Center
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
network
low complexity
avaya CWE-119
8.8
2017-11-10 CVE-2017-11309 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Avaya IP Office
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
network
low complexity
avaya CWE-119
critical
9.6
2017-11-09 CVE-2017-16671 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
low complexity
digium CWE-119
8.8
2017-11-09 CVE-2017-16669 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.
network
low complexity
graphicsmagick debian CWE-119
8.8
2017-11-08 CVE-2017-12824 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Inpage
Special crafted InPage document leads to arbitrary code execution in InPage reader.
local
low complexity
inpage CWE-119
7.8
2017-11-06 CVE-2017-14016 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Advantech Webaccess
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817.
network
low complexity
advantech CWE-119
6.3