VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 33 of 727
  • CVE-2023-42789CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.03

    A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12,…

  • CVE-2024-28553CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

  • CVE-2024-28535CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

  • CVE-2024-27228CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.01

    there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27227CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.00

    A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues

  • CVE-2024-0039CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.02

    In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-2184CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C…

  • CVE-2023-28582CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.

  • CVE-2024-20018CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.

  • CVE-2023-7244CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code…

  • CVE-2023-7243CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write while analyzing specific Ethercat datagrams. This could allow an attacker to cause arbitrary code execution.

  • CVE-2024-23606CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2024-23305CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger…

  • CVE-2024-21795CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2023-52370CriFeb 18, 2024
    risk 0.64cvss 9.8epss 0.00

    Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.

  • CVE-2024-0031CriFeb 16, 2024
    risk 0.64cvss 9.8epss 0.01

    In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-24188CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.

  • CVE-2024-24186CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

  • CVE-2024-1283CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.19

    Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-22852CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.