VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 100 of 727
  • CVE-2018-11420CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.01

    There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a different vulnerability than CVE-2018-11423.

  • CVE-2019-7264CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.

  • CVE-2019-4087CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.07

    IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote…

  • CVE-2019-10991CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.09

    In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.

  • CVE-2019-10989CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.09

    In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability…

  • CVE-2019-12900CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.08

    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

  • CVE-2019-12899CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

  • CVE-2019-12898CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

  • CVE-2019-2007CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.01

    In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed…

  • CVE-2019-2006CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.01

    In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-3954CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.04

    Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.

  • CVE-2019-3953CriJun 18, 2019
    risk 0.64cvss 9.8epss 0.04

    Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 10012 RPC call.

  • CVE-2019-12835CriJun 15, 2019
    risk 0.64cvss 9.8epss 0.01

    formats/xml.cpp in Leanify 0.4.3 allows for a controlled out-of-bounds write in xml_memory_writer::write via characters that require escaping.

  • CVE-2018-6349CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.02

    When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for Android prior to 2.18.248 and WhatsApp Business for Android prior to 2.18.132.

  • CVE-2018-20655CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.02

    When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for iOS prior to v2.18.90.24 and WhatsApp Business for iOS prior to v2.18.90.24.

  • CVE-2018-13898CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.01

    Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9206, MDM9607,…

  • CVE-2019-10126CriJun 14, 2019
    risk 0.64cvss 9.8epss 0.07

    A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.

  • CVE-2019-12553CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.02

    In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

  • CVE-2019-5391CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.03

    A stack buffer overflow vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11356CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.08

    The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.