VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 403 of 734
  • CVE-2021-22754HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.

  • CVE-2021-22752HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.

  • CVE-2021-22751HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported…

  • CVE-2021-22750HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.

  • CVE-2021-25408HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25407HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

  • CVE-2020-24473HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-11165HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the length of buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2021-27399HigJun 8, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of…

  • CVE-2021-27390HigJun 8, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.3), Teamcenter Visualization (All versions < V13.1.0.3). The TIFF_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out…

  • CVE-2021-27387HigJun 8, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of…

  • CVE-2021-1526HigJun 4, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in Webex Recording Format (WRF). An attacker…

  • CVE-2021-1503HigJun 4, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording…

  • CVE-2021-22335HigJun 3, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing.

  • CVE-2021-29665HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.

  • CVE-2010-3843HigMay 28, 2021
    risk 0.51cvss 7.8epss 0.00

    The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/ec_gtk_conf.c), an unchecked sscanf() call allows a maliciously placed settings…

  • CVE-2021-27488HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.02

    Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing CATPart files. This could result in an out-of-bounds write past the end of an…

  • CVE-2021-32458HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first…

  • CVE-2021-30499HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.

  • CVE-2021-30498HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.