VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 603 of 731
  • CVE-2022-35447MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b04de.

  • CVE-2022-35012MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via SaveBMP at /linux/main.cpp.

  • CVE-2022-35010MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via asan_interceptors_memintrinsics.cpp.

  • CVE-2022-35008MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp.

  • CVE-2022-35007MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_common_interceptors.inc.

  • CVE-2022-20273MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2022-34526MedJul 29, 2022
    risk 0.42cvss 6.5epss 0.02

    A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.

  • CVE-2022-1482MedJul 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-34503MedJul 22, 2022
    risk 0.42cvss 6.5epss 0.01

    QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

  • CVE-2022-31602MedJul 4, 2022
    risk 0.42cvss 6.4epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information…

  • CVE-2022-20202MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-31054HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.02

    Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request…

  • CVE-2021-42692MedMay 26, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.

  • CVE-2021-3611MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.00

    A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system…

  • CVE-2022-22323MedApr 27, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to…

  • CVE-2022-22312MedApr 27, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to…

  • CVE-2022-29536HigApr 20, 2022
    risk 0.42cvss 7.5epss 0.02

    In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.

  • CVE-2021-32040MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.02

    It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously…

  • CVE-2022-28662MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.2). The affected application contains an out of bounds write past the end of an allocated buffer while parsing specially crafted .NEU files. This could allow an attacker to leverage this vulnerability…

  • CVE-2022-20063MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.00

    In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.