VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 411 of 734
  • CVE-2020-27005HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could result in an out of bounds write past the end of…

  • CVE-2020-27001HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a stack based buffer overflow. An…

  • CVE-2020-27000HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing BMP files. This can result in a memory corruption condition. An attacker…

  • CVE-2021-25249HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an…

  • CVE-2020-27249HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.01

    A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. In version/Instance 0x0004 and…

  • CVE-2020-27248HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.01

    A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. In version/Instance 0x0003 and…

  • CVE-2020-27247HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.01

    A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. In version/Instance 0x0002, an…

  • CVE-2020-13586HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.02

    A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014). A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious…

  • CVE-2020-1910HigFeb 2, 2021
    risk 0.51cvss 7.8epss 0.05

    A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image.

  • CVE-2021-3345HigJan 29, 2021
    risk 0.51cvss 7.8epss 0.01

    _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

  • CVE-2021-22653HigJan 27, 2021
    risk 0.51cvss 7.8epss 0.01

    Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

  • CVE-2021-22641HigJan 27, 2021
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

  • CVE-2021-22637HigJan 27, 2021
    risk 0.51cvss 7.8epss 0.02

    Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to…

  • CVE-2020-36210HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption.

  • CVE-2020-35845HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf.

  • CVE-2020-35844HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4.

  • CVE-2020-27288HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2020-27284HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2020-11185HigJan 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bound issue in WLAN driver while processing vdev responses from firmware due to lack of validation of data received from firmware in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure…

  • CVE-2020-14409HigJan 19, 2021
    risk 0.51cvss 7.8epss 0.01

    SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.