VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 595 of 731
  • CVE-2023-20802MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.00

    In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420976.

  • CVE-2023-20785MedAug 7, 2023
    risk 0.42cvss 6.4epss 0.00

    In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID: ALPS07628524.

  • CVE-2023-37557MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.

  • CVE-2023-22363MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)

  • CVE-2022-28737MedJul 20, 2023
    risk 0.42cvss 6.5epss 0.00

    There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into…

  • CVE-2021-32256MedJul 18, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

  • CVE-2023-37837MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.01

    libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2023-20771MedJul 4, 2023
    risk 0.42cvss 6.4epss 0.00

    In display, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671046; Issue ID: ALPS07671046.

  • CVE-2023-2290MedJun 26, 2023
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-34620HigJun 14, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

  • CVE-2023-0668MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

  • CVE-2023-0667MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark

  • CVE-2023-0666MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

  • CVE-2023-20736MedJun 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645189.

  • CVE-2023-1945MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.

  • CVE-2023-2798HigMay 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of…

  • CVE-2023-1972MedMay 17, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

  • CVE-2023-1729MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

  • CVE-2023-31146HigMay 11, 2023
    risk 0.42cvss 7.5epss 0.01

    Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, the length word of a dynarray is written before the data, which can result in out-of-bounds array access in the case where the dynarray is on both the lhs and…

  • CVE-2023-31556MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.