VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 642 of 727
  • CVE-2021-33086MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-38959MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.

  • CVE-2021-26330MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

  • CVE-2020-23904MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.

  • CVE-2020-23901MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x5d15 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.

  • CVE-2020-23899MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x5f91 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.

  • CVE-2020-23898MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x5ea2 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.

  • CVE-2020-23897MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor!TMethodImplementationIntercept+0x54dcec of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.

  • CVE-2020-23896MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x576b of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.

  • CVE-2020-23895MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x76af of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.

  • CVE-2020-23894MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in ntdll!RtlpCoalesceFreeBlocks+0x268 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.

  • CVE-2020-23893MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor!TMethodImplementationIntercept+0x3c3682 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.

  • CVE-2020-23891MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor+0x5cd7 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.

  • CVE-2020-23889MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV starting at Editor!TMethodImplementationIntercept+0x4189c6 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted ico file.

  • CVE-2020-23888MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A User Mode Write AV in Editor!TMethodImplementationIntercept+0x53f6c3 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted psd file.

  • CVE-2020-23887MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.

  • CVE-2020-23886MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.

  • CVE-2021-22465MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.

  • CVE-2020-22678MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

  • CVE-2020-22677MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.