VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 408 of 734
  • CVE-2021-27380HigMar 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write past the end…

  • CVE-2020-28385HigMar 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data when parsing DFT files. This could result in an out of bounds write past the end…

  • CVE-2021-21082HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the…

  • CVE-2021-21077HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.07

    Adobe Animate version 21.0.3 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2021-21071HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Animate version 21.0.3 (and earlier) is affected by a Memory Corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-21067HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current…

  • CVE-2021-0465HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0464HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0393HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.01

    In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if an attacker can supply a malicious PAC file, with no additional execution privileges needed. User interaction is…

  • CVE-2021-27365HigMar 7, 2021
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up…

  • CVE-2021-28026HigMar 5, 2021
    risk 0.51cvss 7.8epss 0.01

    jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service.

  • CVE-2021-3404HigMar 4, 2021
    risk 0.51cvss 7.8epss 0.02

    In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

  • CVE-2021-22683HigMar 3, 2021
    risk 0.51cvss 7.8epss 0.01

    Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2021-22666HigMar 3, 2021
    risk 0.51cvss 7.8epss 0.01

    Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2021-24091HigFeb 25, 2021
    risk 0.51cvss 7.8epss 0.03

    Windows Camera Codec Pack Remote Code Execution Vulnerability

  • CVE-2021-24083HigFeb 25, 2021
    risk 0.51cvss 7.8epss 0.03

    Windows Address Book Remote Code Execution Vulnerability

  • CVE-2021-24081HigFeb 25, 2021
    risk 0.51cvss 7.8epss 0.02

    Microsoft Windows Codecs Library Remote Code Execution Vulnerability

  • CVE-2021-21066HigFeb 25, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2021-21065HigFeb 25, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2020-7836HigFeb 24, 2021
    risk 0.51cvss 7.8epss 0.01

    VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improper bound checking parameter given by attack. It finally leads to a stack-based buffer overflow via access to crafted web page.