VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 611 of 727
  • CVE-2024-8948HigSep 17, 2024
    risk 0.41cvss 7.3epss 0.01

    A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2024-8946HigSep 17, 2024
    risk 0.41cvss 7.3epss 0.01

    A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack…

  • CVE-2024-5931MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    BT: Unchecked user input in bap_broadcast_assistant

  • CVE-2024-8408MedSep 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based…

  • CVE-2024-38207MedAug 23, 2024
    risk 0.41cvss 6.3epss 0.00

    Microsoft Edge (HTML-based) Memory Corruption Vulnerability

  • CVE-2024-7272MedAug 12, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. This issue…

  • CVE-2024-7055MedAug 6, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit…

  • CVE-2023-47252MedApr 26, 2024
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication…

  • CVE-2024-32302MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

  • CVE-2023-52364MedApr 8, 2024
    risk 0.41cvss 6.3epss 0.00

    Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.

  • CVE-2024-29131HigMar 21, 2024
    risk 0.41cvss 7.3epss 0.02

    Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

  • CVE-2024-28123HigMar 21, 2024
    risk 0.41cvss 7.3epss 0.01

    Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will arise if the host calls or resumes a Wasm function with more parameters than the default limit (128), as…

  • CVE-2024-22419HigJan 18, 2024
    risk 0.41cvss 7.3epss 0.01

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thus overwrite existing valid data. The root cause is that the `build_IR` for `concat` doesn't…

  • CVE-2024-0540MedJan 15, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely.…

  • CVE-2023-7214MedJan 7, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v8…

  • CVE-2023-7213MedJan 7, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerability is the function main of the file /cgi-bin/cstecgi.cgi?action=login&flag=1 of the component HTTP POST Request Handler. The manipulation of the argument v33…

  • CVE-2023-6888MedDec 17, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in PHZ76 RtspServer 1.0.0. This vulnerability affects the function ParseRequestLine of the file RtspMesaage.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been…

  • CVE-2023-40307MedSep 28, 2023
    risk 0.41cvss 6.3epss 0.00

    An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of…

  • CVE-2022-37331HigJul 21, 2023
    risk 0.41cvss 7.3epss 0.01

    An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2023-1388MedJun 7, 2023
    risk 0.41cvss 6.3epss 0.01

    A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming unavailable.