VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 594 of 731
  • CVE-2020-19190MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19189MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19188MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19187MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19186MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-19185MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

  • CVE-2020-18839MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

  • CVE-2020-18652MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted webp file.

  • CVE-2020-18651MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.

  • CVE-2020-18382MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.

  • CVE-2023-29182MedAug 17, 2023
    risk 0.42cvss 6.4epss 0.00

    A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.

  • CVE-2023-38858MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.

  • CVE-2023-38856MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the get_string function in xlstool.c:411.

  • CVE-2023-38855MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the get_string function in xlstool.c:395.

  • CVE-2023-38854MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcode_latin1_to_utf8 function in xlstool.c:296.

  • CVE-2023-38853MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1015.

  • CVE-2023-38852MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the unicode_decode_wcstombs function in xlstool.c:266.

  • CVE-2023-38851MedAug 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1018.

  • CVE-2023-40294MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.01

    libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_parseBlockI at i_parse_blk.c.

  • CVE-2023-20803MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.00

    In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374.