VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 563 of 731
  • CVE-2022-26430MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS07032521.

  • CVE-2022-26427MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085540; Issue ID: ALPS07085540.

  • CVE-2022-26426MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085486; Issue ID: ALPS07085486.

  • CVE-2022-21792MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085410; Issue ID: ALPS07085410.

  • CVE-2022-32961MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2022-32960MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for card number. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2022-32959MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for OS information. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2021-44170MedJul 18, 2022
    risk 0.44cvss 6.7epss 0.00

    A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.

  • CVE-2021-33656MedJul 18, 2022
    risk 0.44cvss 6.8epss 0.01

    When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

  • CVE-2022-21787MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In audio DSP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558844; Issue ID: ALPS06558844.

  • CVE-2022-21785MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06807363; Issue ID: ALPS06807363.

  • CVE-2022-21784MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704462.

  • CVE-2022-21783MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704482.

  • CVE-2022-21782MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704508.

  • CVE-2022-21781MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704433.

  • CVE-2022-21780MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704526.

  • CVE-2022-21779MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704393.

  • CVE-2022-21766MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641653.

  • CVE-2022-21765MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641673.

  • CVE-2022-31601MedJul 4, 2022
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.