CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 632 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37139 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2023 | ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). | ||
| CVE-2020-23910 | Med | 0.36 | 5.5 | 0.00 | Jul 18, 2023 | Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c. | ||
| CVE-2023-37770 | Med | 0.36 | 5.5 | 0.00 | Jul 17, 2023 | faust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.cpp. | ||
| CVE-2023-37767 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so. | ||
| CVE-2023-37766 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so. | ||
| CVE-2023-37765 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so. | ||
| CVE-2023-37174 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c. | ||
| CVE-2023-32395 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2023 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system. | ||
| CVE-2023-26965 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2023 | loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. | ||
| CVE-2023-34824 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2023 | fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c. | ||
| CVE-2023-34823 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2023 | fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c. | ||
| CVE-2023-2157 | Med | 0.36 | 5.5 | 0.01 | Jun 6, 2023 | A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing. | ||
| CVE-2023-33613 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key. | ||
| CVE-2023-33693 | Med | 0.36 | 5.5 | 0.00 | Jun 5, 2023 | A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file. | ||
| CVE-2023-33546 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2023 | Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow. NOTE:… | ||
| CVE-2023-30775 | Med | 0.36 | 5.5 | 0.00 | May 19, 2023 | A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c. | ||
| CVE-2023-30774 | Med | 0.36 | 5.5 | 0.01 | May 19, 2023 | A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values. | ||
| CVE-2023-30087 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c. | ||
| CVE-2023-30086 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c. | ||
| CVE-2022-48234 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In FM service , there is a possible missing params check. This could lead to local denial of service in FM service . |
- risk 0.36cvss 5.5epss 0.01
ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray().
- risk 0.36cvss 5.5epss 0.00
Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.
- risk 0.36cvss 5.5epss 0.00
faust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.cpp.
- risk 0.36cvss 5.5epss 0.00
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.
- risk 0.36cvss 5.5epss 0.00
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.
- risk 0.36cvss 5.5epss 0.00
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.
- risk 0.36cvss 5.5epss 0.00
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.
- risk 0.36cvss 5.5epss 0.00
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.
- risk 0.36cvss 5.5epss 0.00
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
- risk 0.36cvss 5.5epss 0.00
fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c.
- risk 0.36cvss 5.5epss 0.00
fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.
- risk 0.36cvss 5.5epss 0.01
A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.
- risk 0.36cvss 5.5epss 0.00
axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.
- risk 0.36cvss 5.5epss 0.00
A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file.
- risk 0.36cvss 5.5epss 0.00
Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow. NOTE:…
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
- risk 0.36cvss 5.5epss 0.01
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
- risk 0.36cvss 5.5epss 0.00
Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.
- risk 0.36cvss 5.5epss 0.00
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
- risk 0.36cvss 5.5epss 0.00
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .