VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 639 of 727
  • CVE-2021-4214MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.01

    A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

  • CVE-2022-36233MedAug 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.

  • CVE-2022-2869MedAug 17, 2022
    risk 0.36cvss 5.5epss 0.00

    libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with…

  • CVE-2022-2867MedAug 17, 2022
    risk 0.36cvss 5.5epss 0.00

    libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further…

  • CVE-2022-36150MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    tifig v0.2.2 was discovered to contain a heap-buffer overflow via __asan_memmove at /asan/asan_interceptors_memintrinsics.cpp.

  • CVE-2022-35113MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c.

  • CVE-2022-35109MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

  • CVE-2022-35105MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via /bin/png2swf+0x552cea.

  • CVE-2022-35104MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::reset() at /xpdf/Stream.cc.

  • CVE-2022-35101MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memset-vec-unaligned-erms.S.

  • CVE-2022-35219MedAug 2, 2022
    risk 0.36cvss 5.5epss 0.00

    The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

  • CVE-2022-35218MedAug 2, 2022
    risk 0.36cvss 5.5epss 0.00

    The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

  • CVE-2021-33464MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.

  • CVE-2021-33448MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.

  • CVE-2021-33443MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.

  • CVE-2021-33438MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in json_parse_array() in mjs.c.

  • CVE-2022-34502MedJul 22, 2022
    risk 0.36cvss 5.5epss 0.00

    Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.

  • CVE-2022-34291MedJul 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process.…

  • CVE-2022-34290MedJul 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process.…

  • CVE-2022-34287MedJul 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process.…