VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 640 of 727
  • CVE-2022-32441MedJul 7, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write Address starting at msvcrt!memcpy+0x0000000000000056.

  • CVE-2021-40942MedJun 27, 2022
    risk 0.36cvss 5.5epss 0.01

    In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).

  • CVE-2021-3675MedJun 16, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior…

  • CVE-2021-41458MedJun 16, 2022
    risk 0.36cvss 5.5epss 0.01

    In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.

  • CVE-2022-26745MedMay 26, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.6.6. A malicious application may disclose restricted memory.

  • CVE-2022-28193MedApr 27, 2022
    risk 0.36cvss 5.6epss 0.00

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of…

  • CVE-2022-28506MedApr 25, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

  • CVE-2022-27135MedApr 25, 2022
    risk 0.36cvss 5.5epss 0.01

    xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

  • CVE-2021-3721MedApr 22, 2022
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local access to trigger a blue screen error.

  • CVE-2020-13495MedApr 18, 2022
    risk 0.36cvss 5.5epss 0.01

    An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability…

  • CVE-2022-28966MedApr 16, 2022
    risk 0.36cvss 5.5epss 0.01

    Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in m3_compile.c).

  • CVE-2022-27419MedApr 12, 2022
    risk 0.36cvss 5.5epss 0.01

    rtl_433 21.12 was discovered to contain a stack overflow in the function acurite_00275rm_decode at /devices/acurite.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2022-27146MedApr 8, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.

  • CVE-2022-27145MedApr 8, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.

  • CVE-2022-1068MedApr 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration field. This may cause the program to crash when a long character string is used.

  • CVE-2022-25106MedMar 4, 2022
    risk 0.36cvss 5.5epss 0.09

    D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

  • CVE-2022-22899MedFeb 17, 2022
    risk 0.36cvss 5.5epss 0.01

    Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

  • CVE-2022-0529MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2021-37107MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an improper memory access permission configuration on ACPU.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-46480MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).