VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 624 of 727
  • CVE-2026-73066MedAug 11, 2026
    risk 0.37cvss epss 0.00

    Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution…

  • CVE-2026-71969MedAug 10, 2026
    risk 0.37cvss 6.7epss 0.00

    OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap…

  • CVE-2026-14063MedJun 30, 2026
    risk 0.37cvss 5.7epss 0.00

    Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Low)

  • CVE-2026-53196MedJun 25, 2026
    risk 0.37cvss 6.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_obj(), which is sizeof(struct…

  • CVE-2025-21072MedDec 2, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21071MedNov 5, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-60015MedOct 15, 2025
    risk 0.37cvss 5.7epss 0.00

    An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-21044MedOct 10, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-59730MedOct 6, 2025
    risk 0.37cvss epss 0.00

    When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution. This…

  • CVE-2025-59729MedOct 6, 2025
    risk 0.37cvss epss 0.00

    When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (0x100000) for example…

  • CVE-2025-21021MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21020MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-57577MedJan 16, 2025
    risk 0.37cvss 5.7epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

  • CVE-2024-44236MedOct 28, 2024
    risk 0.37cvss 5.5epss 0.11

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing a maliciously crafted file may lead to unexpected app termination.

  • CVE-2024-40897MedJul 26, 2024
    risk 0.37cvss 6.7epss 0.00

    Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to…

  • CVE-2023-32466MedJul 24, 2024
    risk 0.37cvss 5.7epss 0.00

    Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or…

  • CVE-2023-32472MedJul 10, 2024
    risk 0.37cvss 5.7epss 0.00

    Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary…

  • CVE-2023-49614MedMay 16, 2024
    risk 0.37cvss 5.7epss 0.00

    Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.

  • CVE-2024-0088MedMay 14, 2024
    risk 0.37cvss 5.5epss 0.19

    NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2023-28401MedNov 14, 2023
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access.