CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 637 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39105 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-38676 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-38673 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-38672 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-38671 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-2984 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-35081 | Med | 0.36 | 5.5 | 0.00 | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. | ||
| CVE-2022-35080 | Med | 0.36 | 5.5 | 0.00 | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c. | ||
| CVE-2022-41420 | Med | 0.36 | 5.5 | 0.00 | Oct 3, 2022 | nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component | ||
| CVE-2022-41844 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088. | ||
| CVE-2022-41842 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. | ||
| CVE-2022-40103 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string. | ||
| CVE-2022-35099 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc. | ||
| CVE-2022-35098 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc. | ||
| CVE-2022-35097 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc. | ||
| CVE-2022-35096 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. | ||
| CVE-2022-35095 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc. | ||
| CVE-2022-35094 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc. | ||
| CVE-2022-35093 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. | ||
| CVE-2022-35092 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c. |
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.
- risk 0.36cvss 5.5epss 0.00
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
- risk 0.36cvss 5.5epss 0.00
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.