CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 102 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7130 | Cri | 0.64 | 9.8 | 0.06 | May 23, 2019 | Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution. | ||
| CVE-2019-7104 | Cri | 0.64 | 9.8 | 0.05 | May 23, 2019 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-11873 | Cri | 0.64 | 9.8 | 0.09 | May 23, 2019 | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length,… | ||
| CVE-2019-7832 | Cri | 0.64 | 9.8 | 0.06 | May 22, 2019 | Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.… | ||
| CVE-2019-7804 | Cri | 0.64 | 9.8 | 0.08 | May 22, 2019 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful… | ||
| CVE-2019-12208 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c. | ||
| CVE-2019-12206 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c. | ||
| CVE-2019-12158 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2019 | GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension. | ||
| CVE-2019-5953 | Cri | 0.64 | 9.8 | 0.05 | May 17, 2019 | Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors. | ||
| CVE-2018-18912 | Cri | 0.64 | 9.8 | 0.03 | May 13, 2019 | An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code. | ||
| CVE-2018-4029 | Cri | 0.64 | 9.8 | 0.03 | May 13, 2019 | An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code… | ||
| CVE-2018-4023 | Cri | 0.64 | 9.8 | 0.03 | May 13, 2019 | An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. | ||
| CVE-2018-4014 | Cri | 0.64 | 9.8 | 0.02 | May 13, 2019 | An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this… | ||
| CVE-2019-11839 | Cri | 0.64 | 9.8 | 0.02 | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling. | ||
| CVE-2019-11838 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling. | ||
| CVE-2019-11835 | Cri | 0.64 | 9.8 | 0.03 | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | ||
| CVE-2019-11834 | Cri | 0.64 | 9.8 | 0.03 | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | ||
| CVE-2019-2047 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2019 | In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android… | ||
| CVE-2019-2046 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2019 | In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2019-2045 | Cri | 0.64 | 9.8 | 0.02 | May 8, 2019 | In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android… |
- risk 0.64cvss 9.8epss 0.06
Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution.
- risk 0.64cvss 9.8epss 0.05
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.09
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length,…
- risk 0.64cvss 9.8epss 0.06
Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.…
- risk 0.64cvss 9.8epss 0.08
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful…
- risk 0.64cvss 9.8epss 0.02
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c.
- risk 0.64cvss 9.8epss 0.02
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.
- risk 0.64cvss 9.8epss 0.01
GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.
- risk 0.64cvss 9.8epss 0.05
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code…
- risk 0.64cvss 9.8epss 0.03
An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.
- risk 0.64cvss 9.8epss 0.02
An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this…
- risk 0.64cvss 9.8epss 0.02
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.
- risk 0.64cvss 9.8epss 0.01
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.
- risk 0.64cvss 9.8epss 0.03
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
- risk 0.64cvss 9.8epss 0.03
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
- risk 0.64cvss 9.8epss 0.02
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…
- risk 0.64cvss 9.8epss 0.02
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.02
In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…