VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 450 of 734
  • CVE-2018-5476HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.02

    A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dop or .dpb files may allow an attacker to remotely execute…

  • CVE-2017-16747HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

  • CVE-2018-0893HigMar 14, 2018
    risk 0.51cvss 7.5epss 0.26

    Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876,…

  • CVE-2018-8100HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.01

    The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.

  • CVE-2017-6286HigMar 12, 2018
    risk 0.51cvss 7.8epss 0.00

    NVIDIA libnvomx contains a possible out of bounds write due to a missing bounds check which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-64893247. Reference: N-CVE-2017-6286.

  • CVE-2017-6281HigMar 12, 2018
    risk 0.51cvss 7.8epss 0.00

    NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.

  • CVE-2016-5314HigMar 12, 2018
    risk 0.51cvss 8.8epss 0.05

    Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the…

  • CVE-2017-17227HigMar 9, 2018
    risk 0.51cvss 7.8epss 0.01

    GPU driver in Huawei Mate 10 smart phones with the versions before ALP-L09 8.0.0.120(C212); The versions before ALP-L09 8.0.0.127(C900); The versions before ALP-L09 8.0.0.128(402/C02/C109/C346/C432/C652) has a out-of-bounds memory access vulnerability due to the input parameters…

  • CVE-2018-7487HigFeb 26, 2018
    risk 0.51cvss 7.8epss 0.02

    There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact.

  • CVE-2017-13231HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID:…

  • CVE-2018-1000032HigFeb 9, 2018
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.

  • CVE-2018-1000031HigFeb 9, 2018
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.

  • CVE-2017-6279HigFeb 6, 2018
    risk 0.51cvss 7.8epss 0.00

    NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Android. Version: N/A. Android:…

  • CVE-2017-6258HigFeb 6, 2018
    risk 0.51cvss 7.8epss 0.00

    NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Android. Version: N/A. Android:…

  • CVE-2018-6462HigJan 31, 2018
    risk 0.51cvss 7.8epss 0.03

    Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.

  • CVE-2017-17969HigJan 30, 2018
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

  • CVE-2017-16554HigJan 16, 2018
    risk 0.51cvss 7.8epss 0.00

    K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.

  • CVE-2017-16552HigJan 16, 2018
    risk 0.51cvss 7.8epss 0.00

    K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.

  • CVE-2017-16549HigJan 16, 2018
    risk 0.51cvss 7.8epss 0.00

    K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.

  • CVE-2017-13217HigJan 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without verifying that it's null-terminated. This could lead to a secure boot bypass and a local elevation of privilege enabling code execution as a privileged process with no additional…