Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-9639 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fujielectric V-Server 3.3.22.0
An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior.
network
low complexity
fujielectric CWE-119
7.3
2017-07-17 CVE-2017-10983 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freeradius
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of service.
network
low complexity
freeradius CWE-119
7.5
2017-07-17 CVE-2017-10978 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
network
low complexity
freeradius debian redhat CWE-119
7.5
2017-07-17 CVE-2017-2344 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Juniper Junos
A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow.
local
low complexity
juniper CWE-119
7.8
2017-07-17 CVE-2017-11362 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in PHP
In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.
network
low complexity
php CWE-119
critical
9.8
2017-07-17 CVE-2017-11345 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Asuswrt-Merlin Project products
Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response.
local
low complexity
asuswrt-merlin-project CWE-119
7.8
2017-07-17 CVE-2017-11344 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Asuswrt-Merlin Project products
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.
local
low complexity
asuswrt-merlin-project CWE-119
7.8
2017-07-17 CVE-2017-11339 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Exiv2 0.26
There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26.
network
low complexity
exiv2 CWE-119
6.5
2017-07-17 CVE-2017-11328 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Virustotal Yara
Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.
local
low complexity
virustotal CWE-119
5.5
2017-07-17 CVE-2017-11311 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Openmpt Libopenmpt and Openmpt
soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.
local
low complexity
openmpt CWE-119
7.8