VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 568 of 731
  • CVE-2021-38522MedAug 11, 2021
    risk 0.44cvss 6.8epss 0.01

    NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.

  • CVE-2020-36430HigJul 20, 2021
    risk 0.44cvss 7.8epss 0.01

    libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.

  • CVE-2021-0585MedJul 14, 2021
    risk 0.44cvss 6.7epss 0.00

    In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-33889MedJul 2, 2021
    risk 0.44cvss 6.8epss 0.00

    OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data type for metric_len.

  • CVE-2020-36402HigJul 1, 2021
    risk 0.44cvss 7.8epss 0.01

    Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change.

  • CVE-2021-0546MedJun 22, 2021
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0545MedJun 22, 2021
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-0544MedJun 22, 2021
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0543MedJun 22, 2021
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0540MedJun 22, 2021
    risk 0.44cvss 6.7epss 0.00

    In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0467MedJun 14, 2021
    risk 0.44cvss 6.8epss 0.00

    In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-28211MedJun 11, 2021
    risk 0.44cvss 6.7epss 0.00

    A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

  • CVE-2021-25396MedJun 11, 2021
    risk 0.44cvss 6.7epss 0.00

    An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-22130MedJun 3, 2021
    risk 0.44cvss 6.7epss 0.01

    A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose sys cpuset` with a large…

  • CVE-2021-20515MedApr 30, 2021
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.

  • CVE-2021-20294HigApr 29, 2021
    risk 0.44cvss 7.8epss 0.03

    A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to…

  • CVE-2020-35979HigApr 21, 2021
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.

  • CVE-2021-0488MedApr 15, 2021
    risk 0.44cvss 6.7epss 0.00

    In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0461MedMar 10, 2021
    risk 0.44cvss 6.7epss 0.00

    In iaxxx_core_sensor_change_state of iaxxx-module.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0457MedMar 10, 2021
    risk 0.44cvss 6.7epss 0.00

    In the FingerTipS touch screen driver, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…