VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 634 of 727
  • CVE-2022-45587MedFeb 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.

  • CVE-2022-45586MedFeb 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.

  • CVE-2023-20949MedFeb 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-47452MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-47369MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-47368MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-47366MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-47365MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-47364MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-44448MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-42783MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2022-38675MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2021-36535MedFeb 3, 2023
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.

  • CVE-2022-31902MedFeb 1, 2023
    risk 0.36cvss 5.5epss 0.01

    Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

  • CVE-2022-20235MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written by the GPU driver itself, but prior to DDK 1.18 however, a user-space program could write arbitrary data to the page, leading to memory corruption…

  • CVE-2023-24056MedJan 22, 2023
    risk 0.36cvss 5.5epss 0.01

    In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

  • CVE-2021-46791MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.

  • CVE-2022-47086MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c

  • CVE-2022-44431MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-44430MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.