CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 641 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46478 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS). | ||
| CVE-2021-46477 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS). | ||
| CVE-2021-46475 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS). | ||
| CVE-2021-46474 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS). | ||
| CVE-2021-46238 | Med | 0.36 | 5.5 | 0.01 | Jan 21, 2022 | GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS). | ||
| CVE-2021-46168 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2022 | Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. | ||
| CVE-2021-37530 | Med | 0.36 | 5.5 | 0.01 | Jan 12, 2022 | A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c. | ||
| CVE-2021-36410 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2022 | A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265. | ||
| CVE-2021-45833 | Med | 0.36 | 5.5 | 0.01 | Jan 5, 2022 | A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent). | ||
| CVE-2021-45830 | Med | 0.36 | 5.5 | 0.01 | Jan 5, 2022 | A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service. | ||
| CVE-2021-45935 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int). | ||
| CVE-2021-45949 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). | ||
| CVE-2021-45948 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper). | ||
| CVE-2021-45947 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments). | ||
| CVE-2021-45946 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements). | ||
| CVE-2021-45929 | Med | 0.36 | 5.5 | 0.01 | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If). | ||
| CVE-2021-45258 | Med | 0.36 | 5.5 | 0.01 | Dec 22, 2021 | A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash. | ||
| CVE-2021-39048 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2021 | IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. | ||
| CVE-2021-29323 | Med | 0.36 | 5.5 | 0.01 | Nov 19, 2021 | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c. | ||
| CVE-2021-0075 | Med | 0.36 | 5.5 | 0.00 | Nov 17, 2021 | Out-of-bounds write in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow a privileged user to potentially enable denial of service via local access. |
- risk 0.36cvss 5.5epss 0.01
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.01
Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.01
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.01
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.01
GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.01
Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.
- risk 0.36cvss 5.5epss 0.01
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.
- risk 0.36cvss 5.5epss 0.01
A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.
- risk 0.36cvss 5.5epss 0.01
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).
- risk 0.36cvss 5.5epss 0.01
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
- risk 0.36cvss 5.5epss 0.01
Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).
- risk 0.36cvss 5.5epss 0.01
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
- risk 0.36cvss 5.5epss 0.01
Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).
- risk 0.36cvss 5.5epss 0.01
Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments).
- risk 0.36cvss 5.5epss 0.01
Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements).
- risk 0.36cvss 5.5epss 0.01
Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).
- risk 0.36cvss 5.5epss 0.01
A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.
- risk 0.36cvss 5.5epss 0.00
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
- risk 0.36cvss 5.5epss 0.01
OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds write in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow a privileged user to potentially enable denial of service via local access.