VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 511 of 733
  • CVE-2024-53697HigMar 7, 2025
    risk 0.47cvss 7.2epss 0.00

    An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the…

  • CVE-2024-38638HigMar 7, 2025
    risk 0.47cvss 7.2epss 0.00

    An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. …

  • CVE-2025-20931HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.

  • CVE-2025-20929HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Out-of-bounds write in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.

  • CVE-2024-11345HigFeb 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2024-35273HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

  • CVE-2025-0283HigJan 8, 2025
    risk 0.47cvss 7.0epss 0.17

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-12672HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…

  • CVE-2024-11157HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…

  • CVE-2024-53106HigDec 2, 2024
    risk 0.47cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ima: fix buffer overrun in ima_eventdigest_init_common Function ima_eventdigest_init() calls ima_eventdigest_init_common() with HASH_ALGO__LAST which is then used to access the array hash_digest_size[] leading…

  • CVE-2018-9370HigNov 19, 2024
    risk 0.47cvss 7.3epss 0.00

    In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2024-34660HigSep 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

  • CVE-2024-44933HigAug 26, 2024
    risk 0.47cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl() A recent commit has modified the code in __bnxt_reserve_rings() to set the default RSS indirection table to default only when the number of RX rings…

  • CVE-2021-26344HigAug 13, 2024
    risk 0.47cvss 7.2epss 0.00

    An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

  • CVE-2024-34614HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-34612HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-38025HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.02

    Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability

  • CVE-2024-21778HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this…

  • CVE-2023-50330HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.

  • CVE-2023-50244HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these…