VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 532 of 733
  • CVE-2021-1828HigSep 8, 2021
    risk 0.46cvss 7.1epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An application may be able to cause unexpected system termination or write kernel memory.

  • CVE-2021-1099HigJul 21, 2021
    risk 0.46cvss 7.0epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of…

  • CVE-2021-34380HigJun 30, 2021
    risk 0.46cvss 7.0epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

  • CVE-2021-34201HigJun 16, 2021
    risk 0.46cvss 7.1epss 0.01

    D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.

  • CVE-2021-3561HigMay 26, 2021
    risk 0.46cvss 7.1epss 0.01

    An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this…

  • CVE-2021-3549HigMay 26, 2021
    risk 0.46cvss 7.1epss 0.01

    An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this…

  • CVE-2020-13600HigMay 25, 2021
    risk 0.46cvss 7.0epss 0.00

    Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr

  • CVE-2021-31321HigMay 18, 2021
    risk 0.46cvss 7.1epss 0.01

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a…

  • CVE-2021-31320HigMay 18, 2021
    risk 0.46cvss 7.1epss 0.01

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorTable function of their custom fork of the rlottie library. A remote attacker might be able to overwrite heap memory…

  • CVE-2020-28198HigMay 6, 2021
    risk 0.46cvss 7.0epss 0.00

    The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max…

  • CVE-2021-3501HigMay 6, 2021
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to…

  • CVE-2021-31795HigApr 24, 2021
    risk 0.46cvss 7.0epss 0.00

    The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.

  • CVE-2021-28452HigApr 13, 2021
    risk 0.46cvss 7.1epss 0.01

    Microsoft Outlook Memory Corruption Vulnerability

  • CVE-2021-25346HigMar 4, 2021
    risk 0.46cvss 7.1epss 0.01

    A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

  • CVE-2020-11203HigFeb 22, 2021
    risk 0.46cvss 7.1epss 0.00

    Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2020-36207HigJan 26, 2021
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.

  • CVE-2020-11179HigJan 21, 2021
    risk 0.46cvss 7.0epss 0.00

    Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2017-18926HigNov 6, 2020
    risk 0.46cvss 7.1epss 0.03

    raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).

  • CVE-2020-9929HigOct 22, 2020
    risk 0.46cvss 7.1epss 0.00

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to cause unexpected system termination or read kernel memory.

  • CVE-2020-9921HigOct 22, 2020
    risk 0.46cvss 7.0epss 0.00

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with system privileges.