Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-10-11 CVE-2017-15240 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132cef."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15239 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15220 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense VX Search 10.1.12
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring.
network
low complexity
flexense CWE-119
critical
9.8
2017-10-10 CVE-2017-9714 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an out of bound memory access may happen in limCheckRxRSNIeMatch in case incorrect RSNIE is received from the client in assoc request.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-9706 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an array out-of-bounds access can potentially occur in a display driver.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-11067 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentially lead to the use of an out-of-range pointer offset.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-11059 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-11057 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in compatibility mode, flash_data from 64-bit userspace may cause disclosure of kernel memory or a fault due to using a userspace-provided address.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-11056 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while doing sha and cipher operations, a userspace buffer is directly accessed in kernel space potentially leading to a page fault.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-11053 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when qos map set IE of length less than 16 is received in association response or in qos map configure action frame, a buffer overflow can potentially occur in ConvertQosMapsetFrame().
local
low complexity
google CWE-119
7.8