VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 630 of 727
  • CVE-2023-48350MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48349MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48348MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48343MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48340MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-6340MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.

  • CVE-2024-21594MedJan 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). On an SRX 5000 Series device, when executing a specific command repeatedly,…

  • CVE-2023-37644MedJan 11, 2024
    risk 0.36cvss 5.5epss 0.00

    SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

  • CVE-2023-46835MedJan 5, 2024
    risk 0.36cvss 5.5epss 0.00

    The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels. However dom_io being a PV domain gets the AMD-Vi IOMMU page tables levels…

  • CVE-2023-42557MedDec 5, 2023
    risk 0.36cvss 5.6epss 0.00

    Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.

  • CVE-2022-48464MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2022-48463MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2022-48462MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-42366MedNov 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.

  • CVE-2023-47051MedNov 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2023-47046MedNov 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2023-3164MedNov 2, 2023
    risk 0.36cvss 5.5epss 0.00

    A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

  • CVE-2023-42653MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges

  • CVE-2022-48455MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2022-48454MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed