VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 480 of 734
  • CVE-2023-31922HigMay 12, 2023
    risk 0.49cvss 7.5epss 0.01

    QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.

  • CVE-2023-20524HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

  • CVE-2021-46764HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.

  • CVE-2021-46763HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.

  • CVE-2023-32111HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of…

  • CVE-2023-29995HigMay 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c

  • CVE-2023-29994HigMay 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.

  • CVE-2023-22640HigMay 3, 2023
    risk 0.49cvss 7.5epss 0.01

    A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0…

  • CVE-2023-25506HigApr 22, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information…

  • CVE-2023-0200HigApr 22, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.

  • CVE-2020-23260HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.

  • CVE-2020-23258HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.

  • CVE-2023-24094HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.

  • CVE-2021-43317HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404

  • CVE-2021-43316HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().

  • CVE-2021-43315HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349

  • CVE-2021-43314HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368

  • CVE-2021-43313HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688.

  • CVE-2021-43312HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239.

  • CVE-2021-43311HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.