CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Also known as: Buffer Overflow, buffer overrun, memory safety
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Overview
CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.