VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 412 of 734
  • CVE-2021-25178HigJan 18, 2021
    risk 0.51cvss 7.8epss 0.03

    An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. This can allow attackers to cause a crash potentially enabling a denial of…

  • CVE-2021-25174HigJan 18, 2021
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).

  • CVE-2020-28386HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing DFT files. This could result in an out of bounds write past the end…

  • CVE-2020-28384HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to a stack based buffer overflow. An…

  • CVE-2020-28383HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of…

  • CVE-2020-28382HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in a out of bounds write past the end…

  • CVE-2020-28381HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into…

  • CVE-2020-26993HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to…

  • CVE-2020-26992HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to…

  • CVE-2020-26989HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.03

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of…

  • CVE-2021-1715HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.04

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2021-0318HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2020-27287HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.03

    Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2020-27281HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.

  • CVE-2020-27275HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.03

    Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2018-11010HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2018-11009HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

  • CVE-2020-26664HigJan 8, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

  • CVE-2020-13545HigJan 6, 2021
    risk 0.51cvss 7.8epss 0.02

    An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon…

  • CVE-2020-35702HigDec 25, 2020
    risk 0.51cvss 7.8epss 0.01

    DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT…