VYPR

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

ClassStableLikelihood: High

Description

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (9,878)

page 174 of 494
  • CVE-2025-6093MedJun 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation of the argument num leads to stack-based buffer overflow. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

  • CVE-2025-24111MedMay 12, 2025
    risk 0.36cvss 5.5epss 0.00

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.

  • CVE-2025-3007MedMar 31, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation of the argument cmd/netmask/pipeout/nettask leads to stack-based buffer overflow. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2017-17811MedDec 21, 2017
    risk 0.36cvss 5.5epss 0.00

    In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.

  • CVE-2017-8202MedNov 22, 2017
    risk 0.36cvss 5.5epss 0.00

    The CameraISP driver of some Huawei smart phones with software of versions earlier than Prague-AL00AC00B205,versions earlier than Prague-AL00BC00B205,versions earlier than Prague-AL00CC00B205,versions earlier than Prague-TL00AC01B205,versions earlier than Prague-TL10AC01B205 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP, the APP can send a specific parameter to the CameraISP driver of the smart phone, causing system reboot.

  • CVE-2017-8184MedNov 22, 2017
    risk 0.36cvss 5.5epss 0.00

    MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access vulnerabilities, leading to sensitive information leakage.

  • CVE-2017-8149MedNov 22, 2017
    risk 0.36cvss 5.5epss 0.00

    The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an out-of-bounds memory access vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. the APP can modify specific data to cause buffer overflow in the next system reboot, causing out-of-bounds memory read which can continuous system reboot.

  • CVE-2017-16898MedNov 20, 2017
    risk 0.36cvss 5.5epss 0.00

    The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.

  • CVE-2017-1000127MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    Exiv2 0.26 contains a heap buffer overflow in tiff parser

  • CVE-2017-1000186MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    In SWFTools, a stack overflow was found in pdf2swf.

  • CVE-2017-1000185MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    In SWFTools, a memcpy buffer overflow was found in gif2swf.

  • CVE-2017-1000176MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    In SWFTools, a memcpy buffer overflow was found in swfc.

  • CVE-2017-1000174MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.00

    In SWFTools, an address access exception was found in swfdump swf_GetBits().

  • CVE-2017-15954MedOct 28, 2017
    risk 0.36cvss 5.5epss 0.00

    bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file.

  • CVE-2017-15953MedOct 28, 2017
    risk 0.36cvss 5.5epss 0.00

    bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.

  • CVE-2017-7097MedOct 23, 2017
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Mail MessageUI" component. It allows attackers to cause a denial of service (memory corruption) via a crafted image.

  • CVE-2017-15372MedOct 16, 2017
    risk 0.36cvss 5.5epss 0.00

    There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.

  • CVE-2017-15370MedOct 16, 2017
    risk 0.36cvss 5.5epss 0.00

    There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.

  • CVE-2017-8703MedOct 13, 2017
    risk 0.36cvss 5.5epss 0.00

    The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".

  • CVE-2015-1206MedOct 6, 2017
    risk 0.36cvss 5.5epss 0.00

    Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.