VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 605 of 731
  • CVE-2021-25518MedDec 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-38479MedOct 22, 2021
    risk 0.42cvss 6.5epss 0.01

    Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions. An attacker can manipulate API functions by writing arbitrary data into the resolved address of a raw pointer.

  • CVE-2021-0690MedOct 6, 2021
    risk 0.42cvss 6.5epss 0.01

    In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-20663MedSep 30, 2021
    risk 0.42cvss 6.5epss 0.01

    libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_connection.c.

  • CVE-2020-20662MedSep 30, 2021
    risk 0.42cvss 6.5epss 0.01

    libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_example1.c.

  • CVE-2021-39518MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.

  • CVE-2020-21606MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_16_fallback function, which can be exploited via a crafted a file.

  • CVE-2020-21604MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.

  • CVE-2020-21603MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.

  • CVE-2020-21602MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.

  • CVE-2020-21601MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.

  • CVE-2020-21600MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.

  • CVE-2020-21599MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.

  • CVE-2020-21597MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.02

    libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

  • CVE-2020-21595MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the mc_luma function, which can be exploited via a crafted a file.

  • CVE-2020-21594MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.

  • CVE-2020-19144MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.

  • CVE-2020-19143MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.

  • CVE-2021-3761HigSep 9, 2021
    risk 0.42cvss 7.5epss 0.01

    Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a…

  • CVE-2021-28136MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in…