VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 507 of 733
  • CVE-2024-1112HigJan 31, 2024
    risk 0.48cvss 7.3epss 0.02

    Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument.

  • CVE-2023-6246HigJan 31, 2024
    risk 0.48cvss 8.4epss 0.05

    A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program…

  • CVE-2023-40548HigJan 29, 2024
    risk 0.48cvss 7.4epss 0.00

    A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer…

  • CVE-2023-42560HigDec 5, 2023
    risk 0.48cvss 7.4epss 0.00

    Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

  • CVE-2023-48695HigDec 5, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to out of bounds write vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2022-43970HigJan 9, 2023
    risk 0.48cvss 7.2epss 0.19

    A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary…

  • CVE-2022-3670HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2022-3667HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate…

  • CVE-2022-3665HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The…

  • CVE-2022-3664HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack…

  • CVE-2022-20769HigSep 30, 2022
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error…

  • CVE-2022-36423HigSep 9, 2022
    risk 0.48cvss 7.4epss 0.00

    OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.

  • CVE-2022-36086HigSep 7, 2022
    risk 0.48cvss 8.4epss 0.01

    linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialized with a size smaller…

  • CVE-2022-26092HigApr 11, 2022
    risk 0.48cvss 7.4epss 0.00

    Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

  • CVE-2021-38578HigMar 3, 2022
    risk 0.48cvss 7.4epss 0.01

    Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

  • CVE-2021-4098HigFeb 11, 2022
    risk 0.48cvss 7.4epss 0.01

    Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-32998HigJan 10, 2022
    risk 0.48cvss 7.4epss 0.01

    The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. INIT START/restore from backup required.

  • CVE-2021-35590MedOct 20, 2021
    risk 0.48cvss 6.3epss 0.89

    Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with…

  • CVE-2021-36134HigSep 27, 2021
    risk 0.48cvss 7.4epss 0.01

    Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS).

  • CVE-2021-3713HigAug 25, 2021
    risk 0.48cvss 7.4epss 0.01

    An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields.…