VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 564 of 731
  • CVE-2022-20233MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-20183MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In hypx_create_blob_dmabuf of faceauth_hypx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20178MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20166MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20152MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid…

  • CVE-2021-35118MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2022-21499MedJun 9, 2022
    risk 0.44cvss 6.7epss 0.01

    KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base…

  • CVE-2022-21759MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In power service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419106; Issue ID: ALPS06419077.

  • CVE-2022-21754MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535953; Issue ID: ALPS06535953.

  • CVE-2022-21753MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

  • CVE-2022-21752MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493873.

  • CVE-2022-21751MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

  • CVE-2022-21750MedJun 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521283; Issue ID: ALPS06521283.

  • CVE-2022-28990HigMay 20, 2022
    risk 0.44cvss 7.8epss 0.00

    WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm.

  • CVE-2022-28185MedMay 17, 2022
    risk 0.44cvss 6.8epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

  • CVE-2021-33124MedMay 12, 2022
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2022-20009MedMay 10, 2022
    risk 0.44cvss 6.8epss 0.00

    In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20108MedMay 3, 2022
    risk 0.44cvss 6.7epss 0.00

    In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330702; Issue ID: DTV03330702.

  • CVE-2022-20106MedMay 3, 2022
    risk 0.44cvss 6.7epss 0.00

    In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.

  • CVE-2022-20105MedMay 3, 2022
    risk 0.44cvss 6.7epss 0.00

    In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.