VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 554 of 733
  • CVE-2023-20804MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.

  • CVE-2023-20797MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629582; Issue ID: ALPS07629582.

  • CVE-2023-20795MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ALPS07864900.

  • CVE-2023-20786MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.

  • CVE-2023-20784MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826989; Issue ID: ALPS07826989.

  • CVE-2023-20783MedAug 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826905; Issue ID: ALPS07826905.

  • CVE-2023-35012MedJul 17, 2023
    risk 0.44cvss 6.7epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with SYSADM privileges could overflow the buffer and execute arbitrary code on…

  • CVE-2023-30670MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30669MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30668MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30653MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-30652MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-30651MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-30650MedJul 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-21640MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux when the file upload API is called with parameters having large buffer.

  • CVE-2023-21639MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.

  • CVE-2023-21637MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux while calling system configuration APIs.

  • CVE-2023-21635MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.

  • CVE-2023-21633MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.

  • CVE-2023-20775MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07978760; Issue ID: ALPS07363410.