VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 601 of 731
  • CVE-2022-35066MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

  • CVE-2022-35065MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.

  • CVE-2022-35064MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.

  • CVE-2022-35063MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41a8.

  • CVE-2022-35062MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0bc3.

  • CVE-2022-35061MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.

  • CVE-2022-35060MedSep 19, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.

  • CVE-2022-40151MedSep 16, 2022
    risk 0.42cvss 6.5epss 0.01

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

  • CVE-2022-2402MedSep 6, 2022
    risk 0.42cvss 6.5epss 0.00

    The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

  • CVE-2022-38752MedSep 5, 2022
    risk 0.42cvss 6.5epss 0.02

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.

  • CVE-2022-38751MedSep 5, 2022
    risk 0.42cvss 6.5epss 0.02

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

  • CVE-2022-38750MedSep 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

  • CVE-2022-38749MedSep 5, 2022
    risk 0.42cvss 6.5epss 0.02

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

  • CVE-2021-3826MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.

  • CVE-2021-20298HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

  • CVE-2022-35475MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e41a8.

  • CVE-2022-35474MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b544e.

  • CVE-2022-35472MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a global overflow via /release-x64/otfccdump+0x718693.

  • CVE-2022-35471MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e41b0.

  • CVE-2022-35470MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x65fc97.