VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 6 of 727
  • CVE-2021-28664HigKEVMay 10, 2021
    risk 0.70cvss 8.8epss 0.05

    The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0,…

  • CVE-2020-3118HigKEVFeb 5, 2020
    risk 0.70cvss 8.8epss 0.12

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from…

  • CVE-2019-1429HigKEVNov 12, 2019
    risk 0.70cvss 7.5epss 0.73

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

  • CVE-2019-8050CriAug 20, 2019
    risk 0.70cvss 9.8epss 0.41

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to…

  • CVE-2018-5262CriJan 12, 2018
    risk 0.70cvss 9.8epss 0.39

    A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.

  • CVE-2018-0802HigKEVJan 10, 2018
    risk 0.70cvss 7.8epss 0.87

    Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique…

  • CVE-2015-1641HigKEVApr 14, 2015
    risk 0.70cvss 7.8epss 0.93

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote…

  • CVE-2014-4404HigKEVSep 18, 2014
    risk 0.70cvss 7.8epss 0.49

    Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

  • CVE-2026-11645HigKEVJun 9, 2026
    risk 0.69cvss 8.8epss 0.02

    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3909HigKEVMar 13, 2026
    risk 0.69cvss 8.8epss 0.02

    Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-21043HigKEVSep 12, 2025
    risk 0.69cvss 8.8epss 0.02

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

  • CVE-2024-12084CriJan 15, 2025
    risk 0.69cvss 9.8epss 0.72

    A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2…

  • CVE-2024-30051HigKEVMay 14, 2024
    risk 0.69cvss 7.8epss 0.06

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2023-45878CriNov 14, 2023
    risk 0.69cvss 9.8epss 0.63

    GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the…

  • CVE-2022-41073HigKEVNov 9, 2022
    risk 0.69cvss 7.8epss 0.02

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-35690CriOct 14, 2022
    risk 0.69cvss 9.8epss 0.72

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

  • CVE-2022-24521HigKEVApr 15, 2022
    risk 0.69cvss 7.8epss 0.07

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2021-38406HigKEVSep 17, 2021
    risk 0.69cvss 7.8epss 0.78

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of…

  • CVE-2021-30665HigKEVSep 8, 2021
    risk 0.69cvss 8.8epss 0.04

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is…

  • CVE-2021-35393CriAug 16, 2021
    risk 0.69cvss 9.8epss 0.70

    Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability…