VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 474 of 734
  • CVE-2024-0040HigFeb 16, 2024
    risk 0.49cvss 7.5epss 0.02

    In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-23982HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the…

  • CVE-2023-34351HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2024-25200HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.

  • CVE-2024-20007HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.00

    In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issue ID: ALPS08441369.

  • CVE-2023-6387HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

  • CVE-2024-21780HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported.

  • CVE-2023-52356HigJan 25, 2024
    risk 0.49cvss 7.5epss 0.02

    A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

  • CVE-2023-52110HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-42869HigJan 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues in libxml2.

  • CVE-2023-49427HigJan 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

  • CVE-2022-2081HigJan 4, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the…

  • CVE-2023-49552HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.

  • CVE-2023-32889HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID:…

  • CVE-2023-32888HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161830; Issue ID:…

  • CVE-2023-32887HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161837; Issue ID: MOLY01161837…

  • CVE-2023-32886HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00730807; Issue ID: MOLY00730807.

  • CVE-2021-46901HigDec 31, 2023
    risk 0.49cvss 7.5epss 0.01

    examples/6lbr/apps/6lbr-webserver/httpd.c in CETIC-6LBR (aka 6lbr) 1.5.0 has a strcat stack-based buffer overflow via a request for a long URL over a 6LoWPAN network.

  • CVE-2023-49356HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.

  • CVE-2023-46804HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.04

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).