VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 553 of 733
  • CVE-2023-30695MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary…

  • CVE-2023-30694MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30693MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30689MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30688MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30687MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30686MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-21650MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.

  • CVE-2023-21649MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in WLAN while running doDriverCmd for an unspecific command.

  • CVE-2023-21648MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in RIL while trying to send apdu packet.

  • CVE-2023-20817MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600; Issue ID: ALPS07453600.

  • CVE-2023-20816MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589.

  • CVE-2023-20815MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587; Issue ID: ALPS07453587.

  • CVE-2023-20814MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453560; Issue ID: ALPS07453560.

  • CVE-2023-20811MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.

  • CVE-2023-20809MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03751198; Issue ID: DTV03751198.

  • CVE-2023-20808MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.

  • CVE-2023-20807MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ALPS07608433.

  • CVE-2023-20806MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In hcp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07537437.

  • CVE-2023-20805MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411.