Improper Restriction of Memory Buffer Bounds (CWE-119)
CWE-119 is a Class for operations on a memory buffer that read or write outside the buffer's intended boundary. It covers both directions and both reads and writes, which is why MITRE avoids the ambiguous term buffer overflow. MITRE discourages mapping to it and lists children such as CWE-787 and CWE-125.
About CWE-119
Controlled out-of-bounds access can redirect function pointers and execute code, even when only a single byte is modified. Other outcomes include memory corruption, crashes and reads of sensitive memory.
MITRE marks CWE-119 as DISCOURAGED for mapping real-world vulnerabilities; children such as CWE-787 and CWE-125 are usually a better fit.
Mitigations
- +Choose a memory-safe language, while keeping in mind that native interfaces may still overflow.
- +Use safer string libraries and double-check buffer sizes and loop boundaries.
- +Enable compiler buffer overflow detection mechanisms as defense in depth.
- +Use ASLR and position-independent executables to make exploitation less reliable.
- +Perform root cause analysis and map to the child weakness that describes the actual error.
Detection
Automated static analysis is rated highly effective for buffer errors, and fuzzing plus runtime memory checkers add dynamic coverage.
CWE-119 Vulnerabilities
9 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-7775 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service | NetScaler | 9.2 | 20.3% | KEV | 2025-08-26 |
| CVE-2025-6543 | Memory overflow vulnerability leading to unintended control flow and Denial of Service | NetScaler | 9.2 | 10.6% | KEV | 2025-06-25 |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Cloud Software Group | 8.2 | 57.6% | KEV | 2024-01-17 |
| CVE-2023-4966 | Unauthenticated sensitive information disclosure | Citrix | 9.4 | 100.0% | KEV | 2023-10-10 |
| CVE-2019-8720 | WebKitGTK Memory Corruption Vulnerability | - | 8.8 | 1.6% | KEV | 2023-03-06 |
| CVE-2018-0151 | Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability | - | 9.8 | 14.2% | KEV | 2018-03-28 |
| CVE-2018-0175 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | - | 8.0 | 3.5% | KEV | 2018-03-28 |
| CVE-2018-0167 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | - | 8.8 | 3.4% | KEV | 2018-03-28 |
| CVE-2026-10187 | Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow | Totolink | 10.0 | 7.3% | 2026-05-31 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-119?→
CWE-119 is the MITRE Class for operations that access memory outside a buffer's boundary, whether reading or writing.
Which CWE should replace CWE-119 in a vulnerability record?→
MITRE recommends its children, including CWE-787 for out-of-bounds writes and CWE-125 for out-of-bounds reads.
How many exploited vulnerabilities are classified as CWE-119?→
This database lists 9 CVE records mapped to CWE-119 by their CVE Numbering Authority. 8 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2025-7775, CVE-2025-6543, CVE-2023-6549.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.