VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 551 of 733
  • CVE-2023-32866MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342152; Issue ID: ALPS07342152.

  • CVE-2023-32865MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363456; Issue ID: ALPS07363456.

  • CVE-2023-32864MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292187; Issue ID: ALPS07292187.

  • CVE-2023-32854MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08240132; Issue ID: ALPS08240132.

  • CVE-2023-32853MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In rpmb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648764; Issue ID: ALPS07648764.

  • CVE-2023-32849MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In cmdq, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161758; Issue ID: ALPS08161758.

  • CVE-2023-32848MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

  • CVE-2023-49699MedNov 30, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in IMS while calling VoLTE Streamingmedia Interface

  • CVE-2023-6178MedNov 20, 2023
    risk 0.44cvss 6.8epss 0.01

    An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

  • CVE-2023-6062MedNov 20, 2023
    risk 0.44cvss 6.8epss 0.01

    An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

  • CVE-2023-42529MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42528MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-28570MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while processing audio effects.

  • CVE-2023-32839MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262576; Issue ID: ALPS07262576.

  • CVE-2023-32838MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.

  • CVE-2023-32836MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08126725; Issue ID: ALPS08126725.

  • CVE-2023-21380MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21360MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21310MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-22384MedOct 3, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).