VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 434 of 734
  • CVE-2019-5084HigNov 6, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A specially crafted TIF image can cause an offset beyond the bounds of a heap allocation to be written, potentially resulting in code execution. An attacker can…

  • CVE-2019-2246HigNov 6, 2019
    risk 0.51cvss 7.8epss 0.00

    Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9205, MDM9640,…

  • CVE-2019-5088HigNov 5, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this…

  • CVE-2019-13545HigOct 18, 2019
    risk 0.51cvss 7.8epss 0.02

    In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.

  • CVE-2019-13541HigOct 18, 2019
    risk 0.51cvss 7.8epss 0.02

    In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.

  • CVE-2019-14570HigOct 11, 2019
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

  • CVE-2019-5050HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.03

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

  • CVE-2019-5048HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

  • CVE-2019-5046HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would…

  • CVE-2019-5045HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would…

  • CVE-2019-17262HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.00

    XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.

  • CVE-2019-17261HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.00

    XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.

  • CVE-2019-17259HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.00

    KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.

  • CVE-2019-17258HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000000839c.

  • CVE-2019-17256HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203.

  • CVE-2019-17255HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at EXR!ReadEXR+0x0000000000010836.

  • CVE-2019-17254HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at FORMATS!Read_BadPNG+0x0000000000000101.

  • CVE-2019-17253HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at JPEG_LS+0x000000000000a6b8.

  • CVE-2019-17252HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.03

    IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!Read_BadPNG+0x0000000000000115.

  • CVE-2019-17251HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d43.