VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 641 of 727
  • CVE-2021-46478MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46477MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46475MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46474MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46238MedJan 21, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS).

  • CVE-2021-46168MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.

  • CVE-2021-37530MedJan 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

  • CVE-2021-36410MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.

  • CVE-2021-45833MedJan 5, 2022
    risk 0.36cvss 5.5epss 0.01

    A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).

  • CVE-2021-45830MedJan 5, 2022
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.

  • CVE-2021-45935MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

  • CVE-2021-45949MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

  • CVE-2021-45948MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).

  • CVE-2021-45947MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments).

  • CVE-2021-45946MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements).

  • CVE-2021-45929MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).

  • CVE-2021-45258MedDec 22, 2021
    risk 0.36cvss 5.5epss 0.01

    A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.

  • CVE-2021-39048MedDec 13, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.

  • CVE-2021-29323MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.

  • CVE-2021-0075MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow a privileged user to potentially enable denial of service via local access.