VYPR

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

ClassStableLikelihood: High

Description

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-123 · CAPEC-14 · CAPEC-24 · CAPEC-42 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (14,335)

page 24 of 717
  • CVE-2020-5542CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.02

    Buffer error vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

  • CVE-2020-3754CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3752CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-14006CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2019-14004CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-16463CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to…

  • CVE-2019-16460CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to…

  • CVE-2019-16455CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to…

  • CVE-2019-16446CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to…

  • CVE-2019-10627CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.01

    Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF…

  • CVE-2019-2324CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2019-10541CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…

  • CVE-2019-13508CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.02

    FreeTDS through 1.1.11 has a Buffer Overflow.

  • CVE-2017-14742CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.

  • CVE-2019-11933CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.04

    A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.

  • CVE-2019-8205CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary…

  • CVE-2019-17320CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

  • CVE-2019-9933CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.01

    Various Lexmark products have a Buffer Overflow (issue 3 of 3).

  • CVE-2019-9932CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.01

    Various Lexmark products have a Buffer Overflow (issue 2 of 3).

  • CVE-2019-13484CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.