VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 615 of 727
  • CVE-2019-25565MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows local attackers to crash the application by submitting an oversized input. Attackers can generate a file containing 5000 bytes of data, paste it into the…

  • CVE-2019-25561MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Title field. Attackers can paste a 5000-byte buffer into the Title input field and save the file to trigger a denial…

  • CVE-2019-25558MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a large string of characters into the New Width or New Height field to…

  • CVE-2019-25556MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to…

  • CVE-2019-25550MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog…

  • CVE-2019-25549MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption…

  • CVE-2019-25547MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash the application by supplying oversized input. Attackers can paste a malicious buffer of 512 bytes into the 'Add a website or keyword to be filtered' field and…

  • CVE-2019-25546MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when…

  • CVE-2019-25545MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address'…

  • CVE-2019-25485MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured…

  • CVE-2019-25484MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to crash the application by supplying an oversized payload. Attackers can paste a large string of characters into the User Name and User Code field to trigger a…

  • CVE-2019-25477MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User…

  • CVE-2019-25476MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and…

  • CVE-2019-25475MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service…

  • CVE-2019-25474MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file containing 6000 'A' characters and paste the contents into the Unlock Code field…

  • CVE-2019-25469MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local attackers to crash the application by submitting an oversized payload. Attackers can paste a 6000-byte buffer of arbitrary data into the 'Serial Number and…

  • CVE-2019-25463MedMar 11, 2026
    risk 0.40cvss 6.2epss 0.00

    SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key…

  • CVE-2018-25198MedMar 6, 2026
    risk 0.40cvss 6.2epss 0.00

    eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying oversized input buffers. Attackers can create a payload file containing 255 bytes of data that triggers a buffer overflow condition when processed by the…

  • CVE-2026-20023MedMar 4, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of…

  • CVE-2020-37132MedFeb 5, 2026
    risk 0.40cvss 6.2epss 0.00

    UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and…