VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 607 of 731
  • CVE-2021-0113MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access.

  • CVE-2020-22033MedMay 27, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.

  • CVE-2021-22411MedMay 27, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise…

  • CVE-2020-20266MedMay 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20246MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

  • CVE-2020-20245MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

  • CVE-2020-20227MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

  • CVE-2020-20237MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

  • CVE-2020-20254MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2021-20277HigMay 12, 2021
    risk 0.42cvss 7.5epss 0.04

    A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

  • CVE-2020-20267MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

  • CVE-2020-20265MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.

  • CVE-2020-20247MedMay 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.

  • CVE-2020-20218MedMay 3, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.

  • CVE-2021-22330MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.00

    There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation…

  • CVE-2021-22327MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions…

  • CVE-2021-21222MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2021-31229MedApr 15, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.

  • CVE-2020-36317HigApr 11, 2021
    risk 0.42cvss 7.5epss 0.02

    In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8…

  • CVE-2021-3482MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.