VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 436 of 734
  • CVE-2019-13536HigSep 11, 2019
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-9270HigSep 6, 2019
    risk 0.51cvss 7.8epss 0.00

    In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-6240HigSep 6, 2019
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value to an arbitrary physical address

  • CVE-2019-2181HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2019-2178HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC service with no additional execution privileges needed. User interaction…

  • CVE-2019-2176HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.02

    In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed…

  • CVE-2019-2123HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrary code in a privileged process due to a memory overwrite. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2019-2115HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

  • CVE-2019-2108HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.02

    In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2019-13522HigSep 4, 2019
    risk 0.51cvss 7.8epss 0.01

    An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of the EZ PLC Editor Versions 1.8.41 and prior.

  • CVE-2019-12810HigAug 30, 2019
    risk 0.51cvss 7.8epss 0.02

    A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code execution. By persuading a victim to open a specially-crafted .PSD file, an attacker…

  • CVE-2019-14970HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.03

    A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

  • CVE-2019-15767HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.

  • CVE-2019-15540HigAug 25, 2019
    risk 0.51cvss 7.8epss 0.01

    filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user.

  • CVE-2019-2134HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2019-2133HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android.…

  • CVE-2019-2128HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.00

    In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2019-2127HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.00

    In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.…

  • CVE-2019-13520HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.03

    Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code under the privileges of the application.

  • CVE-2019-1199HigAug 14, 2019
    risk 0.51cvss 7.8epss 0.05

    A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on…