VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 606 of 731
  • CVE-2021-22791MedSep 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions),…

  • CVE-2020-18773MedAug 23, 2021
    risk 0.42cvss 6.5epss 0.01

    An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

  • CVE-2020-21066MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

  • CVE-2020-21677MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.

  • CVE-2021-26096MedAug 4, 2021
    risk 0.42cvss 6.4epss 0.01

    Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.

  • CVE-2020-20219MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20249MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.

  • CVE-2020-23707MedJul 15, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.

  • CVE-2020-23706MedJul 15, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.

  • CVE-2020-20231MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2021-33681MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the application.

  • CVE-2020-19721MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).

  • CVE-2020-20252MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20250MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). NOTE: this is different from CVE-2020-20253 and…

  • CVE-2020-20215MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

  • CVE-2021-34383MedJun 30, 2021
    risk 0.42cvss 6.4epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

  • CVE-2020-7870MedJun 29, 2021
    risk 0.42cvss 6.4epss 0.01

    A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter.

  • CVE-2021-20573MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249.

  • CVE-2021-20572MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247.

  • CVE-2021-20494MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882.