VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 598 of 731
  • CVE-2022-38582MedNov 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.

  • CVE-2022-43253MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43252MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43250MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43249MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43248MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43245MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43244MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43243MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weighted_pred_avg_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43242MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43241MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43240MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43239MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43237MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43236MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-43235MedNov 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

  • CVE-2022-3228MedOct 28, 2022
    risk 0.42cvss 6.5epss 0.00

    Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM100 Communications Module Firmware versions v5.0.155 and prior. This may allow an attacker to crash…

  • CVE-2022-43038MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

  • CVE-2022-43035MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

  • CVE-2022-43034MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.