VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,651)

page 562 of 733
  • CVE-2022-32603MedNov 8, 2022
    risk 0.44cvss 6.7epss 0.00

    In gpu drm, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310704; Issue ID: ALPS07310704.

  • CVE-2022-42830MedNov 1, 2022
    risk 0.44cvss 6.7epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-32593MedOct 7, 2022
    risk 0.44cvss 6.7epss 0.00

    In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138493; Issue ID: ALPS07138493.

  • CVE-2022-32592MedOct 7, 2022
    risk 0.44cvss 6.7epss 0.00

    In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07139405; Issue ID: ALPS07139405.

  • CVE-2022-26475MedOct 7, 2022
    risk 0.44cvss 6.7epss 0.00

    In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310743; Issue ID: ALPS07310743.

  • CVE-2022-3349MedSep 28, 2022
    risk 0.44cvss 6.8epss 0.01

    A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack…

  • CVE-2022-25654MedSep 16, 2022
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2022-20231MedSep 14, 2022
    risk 0.44cvss 6.7epss 0.00

    In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-38495HigSep 13, 2022
    risk 0.44cvss 7.8epss 0.00

    LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.

  • CVE-2022-38306HigSep 13, 2022
    risk 0.44cvss 7.8epss 0.00

    LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.

  • CVE-2022-26470MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In aie, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07116037; Issue ID: ALPS07116037.

  • CVE-2022-26467MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In rpmb, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07167738; Issue ID: ALPS07167738.

  • CVE-2022-26465MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558799; Issue ID: ALPS06558799.

  • CVE-2022-26464MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032699; Issue ID: ALPS07032699.

  • CVE-2022-26460MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032590; Issue ID: ALPS07032590.

  • CVE-2022-26458MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032678; Issue ID: ALPS07032678.

  • CVE-2022-26457MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138490; Issue ID: ALPS07138490.

  • CVE-2022-26455MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In gz, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177858; Issue ID: ALPS07177858.

  • CVE-2022-26449MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177810; Issue ID: ALPS07177810.

  • CVE-2022-26448MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07063849; Issue ID: ALPS07063849.