VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 632 of 727
  • CVE-2023-37139MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.01

    ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray().

  • CVE-2020-23910MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.

  • CVE-2023-37770MedJul 17, 2023
    risk 0.36cvss 5.5epss 0.00

    faust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.cpp.

  • CVE-2023-37767MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.

  • CVE-2023-37766MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.

  • CVE-2023-37765MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.

  • CVE-2023-37174MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.

  • CVE-2023-32395MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.

  • CVE-2023-26965MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.00

    loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

  • CVE-2023-34824MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.00

    fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c.

  • CVE-2023-34823MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.00

    fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.

  • CVE-2023-2157MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.

  • CVE-2023-33613MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.

  • CVE-2023-33693MedJun 5, 2023
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file.

  • CVE-2023-33546MedJun 1, 2023
    risk 0.36cvss 5.5epss 0.00

    Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow. NOTE:…

  • CVE-2023-30775MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.

  • CVE-2023-30774MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.

  • CVE-2023-30087MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.

  • CVE-2023-30086MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.

  • CVE-2022-48234MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .