VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 578 of 731
  • CVE-2025-20639MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2025-20635MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2024-20142MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2024-20141MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2025-0242MedJan 7, 2025
    risk 0.43cvss 6.5epss 0.13

    Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to…

  • CVE-2024-20145MedJan 6, 2025
    risk 0.43cvss 6.6epss 0.00

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2024-20144MedJan 6, 2025
    risk 0.43cvss 6.6epss 0.00

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2024-20143MedJan 6, 2025
    risk 0.43cvss 6.6epss 0.00

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2024-20074MedJun 3, 2024
    risk 0.43cvss 6.6epss 0.00

    In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08668110; Issue ID: MSV-1333.

  • CVE-2024-20073MedJun 3, 2024
    risk 0.43cvss 6.6epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411.

  • CVE-2024-20072MedJun 3, 2024
    risk 0.43cvss 6.6epss 0.00

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.

  • CVE-2024-20054MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

  • CVE-2024-20044MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.

  • CVE-2024-20043MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: ALPS08541781.

  • CVE-2024-20042MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS08541780.

  • CVE-2024-20028MedMar 4, 2024
    risk 0.43cvss 6.6epss 0.00

    In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541687.

  • CVE-2024-20819MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2024-20818MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2024-20817MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2023-28572MedNov 7, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.