VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 496 of 733
  • CVE-2019-16747HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.02

    In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.

  • CVE-2020-35376HigDec 26, 2020
    risk 0.49cvss 7.5epss 0.02

    Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

  • CVE-2020-7837HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer…

  • CVE-2020-29363HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving…

  • CVE-2020-17443HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 echo request packet's size is shorter than 8 bytes. If the size of the incoming ICMPv6 request packet is shorter than this, the operation that calculates the…

  • CVE-2020-13985HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.

  • CVE-2020-29573HigDec 6, 2020
    risk 0.49cvss 7.5epss 0.03

    sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a…

  • CVE-2020-25464HigDec 4, 2020
    risk 0.49cvss 7.5epss 0.01

    Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.

  • CVE-2020-17058HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Microsoft Browser Memory Corruption Vulnerability

  • CVE-2020-17053HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Internet Explorer Memory Corruption Vulnerability

  • CVE-2020-17052HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.03

    Scripting Engine Memory Corruption Vulnerability

  • CVE-2020-9869HigOct 22, 2020
    risk 0.49cvss 7.5epss 0.02

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A remote attacker may cause an unexpected application termination.

  • CVE-2020-24388HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This…

  • CVE-2020-24387HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This…

  • CVE-2020-24266HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.

  • CVE-2020-24265HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.

  • CVE-2020-5138HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12,…

  • CVE-2020-24397HigOct 2, 2020
    risk 0.49cvss 7.2epss 0.28

    An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code…

  • CVE-2020-7122HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the CDP (Cisco Discovery Protocol) process in the switch.…

  • CVE-2020-7121HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the…