Threats Tagged 'cwe-119'
View all threats tagged with 'cwe-119'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-119'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-0409: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer in NETGEAR Orbi 370CVE-2026-0409 0 A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7. Join the discussion | CVE Database V5 | 06/09/2026, 15:39:09 UTC Added: 06/09/2026, 16:25:56 UTC |
CVE-2025-62623: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer in AMD ESXi 8.x and ESXi 9.x hosts using AMD-Pensando DPU productsCVE-2025-62623 0 A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. Join the discussion | CVE Database V5 | 05/13/2026, 02:58:29 UTC Added: 05/13/2026, 03:36:24 UTC |
CVE-2026-22167: CWE - CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer (4.18) in Imagination Technologies Graphics DDKCVE-2026-22167 0 Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory. Join the discussion | CVE Database V5 | 05/01/2026, 15:48:49 UTC Added: 05/01/2026, 16:21:55 UTC |
CVE-2026-7030: Buffer Overflow in Tenda F456CVE-2026-7030 0 A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Join the discussion | GCVE Database | 04/26/2026, 09:15:13 UTC Added: 04/26/2026, 19:47:02 UTC |
CVE-2026-7032: Buffer Overflow in Tenda F456CVE-2026-7032 0 A flaw has been found in Tenda F456 1.0.0.5. Affected is the function SafeEmailFilter of the file /goform/SafeEmailFilter. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. Join the discussion | GCVE Database | 04/26/2026, 10:00:19 UTC Added: 04/26/2026, 19:47:02 UTC |
CVE-2026-7033: Buffer Overflow in Tenda F456CVE-2026-7033 0 A vulnerability has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Such manipulation of the argument menufacturer/Go leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Join the discussion | GCVE Database | 04/26/2026, 10:15:16 UTC Added: 04/26/2026, 19:47:02 UTC |
CVE-2026-7057: Buffer Overflow in Tenda F456CVE-2026-7057 0 CVE-2026-7057 is a high-severity buffer overflow vulnerability in Tenda F456 version 1.0.0.5. It exists in an unknown function within the /goform/setcfm endpoint of the httpd component. The vulnerability is triggered by manipulating the funcname or funcpara1 arguments remotely, potentially allowing an attacker to cause a buffer overflow. No official patch or remediation guidance is currently available, and no known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 04/26/2026, 18:45:15 UTC Added: 04/26/2026, 19:06:06 UTC |
CVE-2026-7056: Buffer Overflow in Tenda F456CVE-2026-7056 0 CVE-2026-7056 is a high-severity buffer overflow vulnerability in the Tenda F456 router version 1.0.0.5. It affects the fromSafeUrlFilter function in the /goform/SafeUrlFilter component of the httpd service. The vulnerability arises from improper handling of the 'page' argument, allowing remote attackers to cause a buffer overflow. Exploit code is publicly available, but no known exploits in the wild have been reported. No official patch or remediation guidance has been provided by the vendor as of now. Join the discussion | CVE Database V5 | 04/26/2026, 18:30:16 UTC Added: 04/26/2026, 18:36:04 UTC |
CVE-2026-7055: Buffer Overflow in Tenda F456CVE-2026-7055 0 CVE-2026-7055 is a high-severity buffer overflow vulnerability in Tenda F456 version 1.0.0.5. It affects the fromVirtualSer function in the /goform/VirtualSer component of the httpd service. The vulnerability arises from improper handling of the menufacturer/Go argument, allowing remote attackers to cause a buffer overflow. This issue has been publicly disclosed, but no known exploits are currently observed in the wild. No official patch or remediation guidance has been provided by the vendor as of the publication date. Join the discussion | CVE Database V5 | 04/26/2026, 18:00:19 UTC Added: 04/26/2026, 18:21:36 UTC |
CVE-2026-7054: Buffer Overflow in Tenda F456CVE-2026-7054 0 CVE-2026-7054 is a high-severity buffer overflow vulnerability in Tenda F456 version 1.0.0.5. It affects the fromPptpUserAdd function in the /goform/PPTPDClient component of the device's HTTP server. The vulnerability arises from improper handling of the opttype/username argument, allowing remote attackers to cause a buffer overflow. Exploit code has been publicly released, increasing the risk of attacks. No official patch or remediation guidance has been provided by the vendor as of the publication date. Join the discussion | CVE Database V5 | 04/26/2026, 16:45:12 UTC Added: 04/26/2026, 17:06:04 UTC |
Showing 1 to 10 of 111 results