VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 550 of 733
  • CVE-2023-33067MedFeb 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.

  • CVE-2024-20013MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Issue ID: ALPS08308608.

  • CVE-2024-20006MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.

  • CVE-2024-20002MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID: DTV03961715.

  • CVE-2024-20001MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID: DTV03961601.

  • CVE-2023-33038MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while receiving a message in Bus Socket Transport Server.

  • CVE-2023-32891MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07933038; Issue ID: MSV-559.

  • CVE-2023-32883MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; Issue ID: ALPS08282249.

  • CVE-2023-32882MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308616.

  • CVE-2023-32879MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308064.

  • CVE-2023-32877MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308070.

  • CVE-2023-32872MedJan 2, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08308607.

  • CVE-2023-33222MedDec 15, 2023
    risk 0.44cvss 6.8epss 0.01

    When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code…

  • CVE-2023-33221MedDec 15, 2023
    risk 0.44cvss 6.8epss 0.01

    When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is…

  • CVE-2023-28580MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.

  • CVE-2023-22383MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in camera while installing a fd for a particular DMA buffer.

  • CVE-2023-21634MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.

  • CVE-2023-32869MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363689.

  • CVE-2023-32868MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363632.

  • CVE-2023-32867MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560793; Issue ID: ALPS07560793.