CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,670)
page 480 of 734| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31922 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2023 | QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c. | ||
| CVE-2023-20524 | Hig | 0.49 | 7.5 | 0.00 | May 9, 2023 | An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity. | ||
| CVE-2021-46764 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service. | ||
| CVE-2021-46763 | Hig | 0.49 | 7.5 | 0.00 | May 9, 2023 | Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity. | ||
| CVE-2023-32111 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of… | ||
| CVE-2023-29995 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2023 | In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c | ||
| CVE-2023-29994 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2023 | In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c. | ||
| CVE-2023-22640 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2023 | A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0… | ||
| CVE-2023-25506 | Hig | 0.49 | 7.5 | 0.00 | Apr 22, 2023 | NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information… | ||
| CVE-2023-0200 | Hig | 0.49 | 7.5 | 0.00 | Apr 22, 2023 | NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. | ||
| CVE-2020-23260 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2023 | An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file. | ||
| CVE-2020-23258 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2023 | An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file. | ||
| CVE-2023-24094 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets. | ||
| CVE-2021-43317 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404 | ||
| CVE-2021-43316 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64(). | ||
| CVE-2021-43315 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349 | ||
| CVE-2021-43314 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368 | ||
| CVE-2021-43313 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688. | ||
| CVE-2021-43312 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239. | ||
| CVE-2021-43311 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382. |
- risk 0.49cvss 7.5epss 0.01
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
- risk 0.49cvss 7.5epss 0.00
An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.
- risk 0.49cvss 7.5epss 0.01
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.
- risk 0.49cvss 7.5epss 0.01
In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of…
- risk 0.49cvss 7.5epss 0.01
In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c
- risk 0.49cvss 7.5epss 0.01
In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.
- risk 0.49cvss 7.5epss 0.01
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0…
- risk 0.49cvss 7.5epss 0.00
NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information…
- risk 0.49cvss 7.5epss 0.00
NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.
- risk 0.49cvss 7.5epss 0.01
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.
- risk 0.49cvss 7.5epss 0.01
An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.
- risk 0.49cvss 7.5epss 0.01
An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688.
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239.
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.