VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 552 of 733
  • CVE-2023-32830MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID: DTV03802522.

  • CVE-2023-32827MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID:…

  • CVE-2023-32826MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID:…

  • CVE-2023-32822MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In ftm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07994229; Issue ID: ALPS07994229.

  • CVE-2023-32821MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In video, there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08013430; Issue ID: ALPS08013433.

  • CVE-2023-21663MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption while accessing metadata in Display.

  • CVE-2023-21654MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio during playback session with audio effects enabled.

  • CVE-2023-32812MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365; Issue ID: ALPS08017365.

  • CVE-2023-32811MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID:…

  • CVE-2023-32806MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589.

  • CVE-2023-20837MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue ID: ALPS07992786.

  • CVE-2023-20832MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08013530.

  • CVE-2023-20831MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014162.

  • CVE-2023-20830MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014156.

  • CVE-2023-20829MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014148.

  • CVE-2023-20828MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014144.

  • CVE-2023-20822MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In netdagent, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944012; Issue ID: ALPS07944012.

  • CVE-2023-20821MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113.

  • CVE-2023-38553MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed

  • CVE-2023-30702MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.