Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2006-3635 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Linux Kernel
The ia64 subsystem in the Linux kernel before 2.6.26 allows local users to cause a denial of service (stack consumption and system crash) via a crafted application that leverages the mishandling of invalid Register Stack Engine (RSE) state.
local
low complexity
linux CWE-119
5.5
2017-08-05 CVE-2017-12562 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
network
low complexity
libsndfile-project debian CWE-119
critical
9.8
2017-08-04 CVE-2017-12482 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ledger-Cli Ledger 3.1.1
The ledger::parse_date_mask_routine function in times.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ledger-cli CWE-119
7.8
2017-08-04 CVE-2017-12481 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ledger-Cli Ledger 3.1.1
The find_option function in option.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ledger-cli CWE-119
7.8
2017-08-04 CVE-2017-12424 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors.
network
low complexity
shadow-project debian CWE-119
critical
9.8
2017-08-03 CVE-2017-11721 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ioquake3 20170227/20170731
Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.
network
low complexity
ioquake3 CWE-119
critical
9.8
2017-08-02 CVE-2017-1495 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Infosphere Information Server 11.3/11.5/9.1
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials.
network
low complexity
ibm CWE-119
4.9
2017-08-02 CVE-2017-2282 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iodata Wn-Ax1167Gr Firmware 3.00
Buffer overflow in WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
low complexity
iodata CWE-119
6.8
2017-08-02 CVE-2017-12141 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
ytnef-project CWE-119
5.5
2017-08-01 CVE-2017-8663 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Outlook
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a remote code execution vulnerability due to the way Microsoft Outlook parses specially crafted email messages, aka "Microsoft Office Outlook Memory Corruption Vulnerability"
local
low complexity
microsoft CWE-119
7.8