VYPR

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

ClassStableLikelihood: High

Description

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (14,335)

page 21 of 717
  • CVE-2020-35527CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

  • CVE-2022-32839CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.04

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code…

  • CVE-2022-29465CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-20238CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:…

  • CVE-2022-26776CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2021-46786CriMay 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.

  • CVE-2021-44496CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of…

  • CVE-2021-22434CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22433CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22432CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-22431CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-22429CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22426CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-3657CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could…

  • CVE-2021-20325CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux…

  • CVE-2021-39997CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-31617CriJan 31, 2022
    risk 0.64cvss 9.8epss 0.02

    In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

  • CVE-2021-45709CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the crypto2 crate through 2021-10-08 for Rust. During Chacha20 encryption and decryption, an unaligned read of a u32 may occur.

  • CVE-2021-40393CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.03

    An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can…

  • CVE-2021-44538CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.02

    The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can…