VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 592 of 731
  • CVE-2024-24581MedApr 2, 2024
    risk 0.42cvss 6.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.

  • CVE-2024-21661HigMar 18, 2024
    risk 0.42cvss 7.5epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all…

  • CVE-2024-20832MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2024-20831MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2023-52355HigJan 25, 2024
    risk 0.42cvss 7.5epss 0.02

    An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

  • CVE-2024-0741MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.02

    An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • CVE-2023-51743MedJan 17, 2024
    risk 0.42cvss 6.5epss 0.01

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted…

  • CVE-2023-51742MedJan 17, 2024
    risk 0.42cvss 6.5epss 0.01

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to…

  • CVE-2023-6129MedJan 9, 2024
    risk 0.42cvss 6.5epss 0.02

    Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether…

  • CVE-2023-51080HigDec 27, 2023
    risk 0.42cvss 7.5epss 0.01

    The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.

  • CVE-2023-48697MedDec 5, 2023
    risk 0.42cvss 6.4epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2022-44011MedNov 23, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16,…

  • CVE-2023-32840MedNov 6, 2023
    risk 0.42cvss 6.5epss 0.00

    In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction may be also needed for exploitation Patch ID: MOLY01138425; Issue ID: MOLY01138425…

  • CVE-2023-47249MedNov 5, 2023
    risk 0.42cvss 6.5epss 0.01

    In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in IccUtilXml.cpp in libIccXML.a has an out-of-bounds read.

  • CVE-2023-45678MedOct 21, 2023
    risk 0.42cvss 6.5epss 0.01

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in `start_decoder` because at maximum `m->submaps` can be 16 but `submap_floor` and `submap_residue` are declared as arrays of 15 elements. This issue…

  • CVE-2023-45675MedOct 21, 2023
    risk 0.42cvss 6.5epss 0.01

    stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if the len read in `start_decoder` is `-1` and `len + 1` becomes 0 when passed to…

  • CVE-2023-41712MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

  • CVE-2023-41711MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.

  • CVE-2023-39280MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.

  • CVE-2023-39279MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.