VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 16 of 727
  • CVE-2020-1380HigKEVAug 17, 2020
    risk 0.65cvss 7.8epss 0.24

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker…

  • CVE-2020-15588CriJul 29, 2020
    risk 0.65cvss 9.8epss 0.13

    An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code…

  • CVE-2020-6103CriJul 20, 2020
    risk 0.65cvss 9.9epss 0.03

    An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability…

  • CVE-2020-6102CriJul 20, 2020
    risk 0.65cvss 9.9epss 0.03

    An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability…

  • CVE-2020-6101CriJul 20, 2020
    risk 0.65cvss 9.9epss 0.03

    An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability…

  • CVE-2020-6100CriJul 20, 2020
    risk 0.65cvss 9.9epss 0.02

    An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerability. An attacker can provide a specially crafted shader file to trigger this vulnerability. This…

  • CVE-2020-1054HigKEVMay 21, 2020
    risk 0.65cvss 7.0epss 0.54

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;…

  • CVE-2020-10828CriMar 26, 2020
    risk 0.65cvss 9.8epss 0.21

    A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

  • CVE-2020-10827CriMar 26, 2020
    risk 0.65cvss 9.8epss 0.21

    A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

  • CVE-2020-10881CriMar 25, 2020
    risk 0.65cvss 9.8epss 0.11

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A…

  • CVE-2019-8600CriDec 18, 2019
    risk 0.65cvss 9.8epss 0.20

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.

  • CVE-2019-14901CriNov 29, 2019
    risk 0.65cvss 9.8epss 0.17

    A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with…

  • CVE-2019-12526CriNov 26, 2019
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to…

  • CVE-2018-8879CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.17

    Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request.…

  • CVE-2019-18240CriNov 13, 2019
    risk 0.65cvss 9.8epss 0.14

    In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-18655CriNov 12, 2019
    risk 0.65cvss 9.8epss 0.15

    File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated attacker is able to perform remote command execution and obtain a command shell by sending a HTTP GET request including the…

  • CVE-2019-5049CriOct 31, 2019
    risk 0.65cvss 10.0epss 0.02

    An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this…

  • CVE-2019-15679CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

  • CVE-2019-15678CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

  • CVE-2019-5482CriSep 16, 2019
    risk 0.65cvss 9.8epss 0.18

    Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.