VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 633 of 727
  • CVE-2022-48233MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .

  • CVE-2022-48232MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .

  • CVE-2022-47340MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2023-29950MedApr 27, 2023
    risk 0.36cvss 5.5epss 0.00

    swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c

  • CVE-2023-30402MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

  • CVE-2023-30414MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.

  • CVE-2023-30410MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.

  • CVE-2023-29583MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted…

  • CVE-2023-29582MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted…

  • CVE-2023-29579MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted…

  • CVE-2023-26554MedApr 11, 2023
    risk 0.36cvss 5.6epss 0.01

    mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

  • CVE-2023-26553MedApr 11, 2023
    risk 0.36cvss 5.6epss 0.01

    mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

  • CVE-2023-26552MedApr 11, 2023
    risk 0.36cvss 5.6epss 0.01

    mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

  • CVE-2023-26551MedApr 11, 2023
    risk 0.36cvss 5.6epss 0.01

    mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

  • CVE-2022-47337MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In media service, there is a missing permission check. This could lead to local denial of service in media service.

  • CVE-2023-20952MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-27249MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

  • CVE-2023-27754MedMar 22, 2023
    risk 0.36cvss 5.5epss 0.00

    vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

  • CVE-2022-47459MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-47457MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.