VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 494 of 733
  • CVE-2021-1809HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to read…

  • CVE-2021-1808HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to read restricted memory.

  • CVE-2020-19131HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

  • CVE-2021-33938HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

  • CVE-2021-33930HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

  • CVE-2021-33929HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

  • CVE-2021-33928HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

  • CVE-2020-20490HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).

  • CVE-2020-20486HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.

  • CVE-2020-18735HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

  • CVE-2020-18734HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

  • CVE-2021-31227HigAug 19, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to an incorrect signed integer comparison. This vulnerability requires the attacker to send a malformed HTTP packet with a…

  • CVE-2020-23334HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.

  • CVE-2020-23333HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).

  • CVE-2020-23332HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).

  • CVE-2021-38614HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-38592HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).

  • CVE-2021-22414HigAug 2, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Memory Buffer Errors Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.

  • CVE-2021-20109HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as…

  • CVE-2020-22907HigJul 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via a crafted value to the execute parameter.