VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 430 of 734
  • CVE-2020-3714HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3713HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3712HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3711HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3710HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-7951HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.02

    meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.

  • CVE-2015-0242HigJan 27, 2020
    risk 0.51cvss 8.8epss 0.05

    Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service…

  • CVE-2015-2325HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.02

    The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward…

  • CVE-2019-9469HigJan 6, 2020
    risk 0.51cvss 7.8epss 0.00

    In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2019-9468HigJan 6, 2020
    risk 0.51cvss 7.8epss 0.00

    In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10…

  • CVE-2013-3939HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based…

  • CVE-2013-3937HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.

  • CVE-2013-3247HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.

  • CVE-2013-3246HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.

  • CVE-2013-3946HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.

  • CVE-2012-4980HigDec 27, 2019
    risk 0.51cvss 7.8epss 0.02

    Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.

  • CVE-2019-19918HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • CVE-2019-8254HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-8253HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-8807HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.