VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 644 of 727
  • CVE-2021-36083MedJul 1, 2021
    risk 0.36cvss 5.5epss 0.01

    KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.

  • CVE-2021-3630MedJun 30, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.

  • CVE-2021-34071MedJun 23, 2021
    risk 0.36cvss 5.5epss 0.01

    Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.

  • CVE-2021-0561MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-12289MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-3569MedJun 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

  • CVE-2021-31323MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds…

  • CVE-2021-31322MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim…

  • CVE-2021-31315MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's stack memory out-of-bounds on a victim device…

  • CVE-2020-23861MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.

  • CVE-2020-23852MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial of service by submitting a malicious jpeg image.

  • CVE-2020-23851MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by submitting a malicious jpeg image.

  • CVE-2021-20546MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the application to crash. IBM X-Force ID: 198934

  • CVE-2021-28686MedApr 8, 2021
    risk 0.36cvss 5.5epss 0.00

    AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoControl.

  • CVE-2021-1760MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute…

  • CVE-2021-20284MedMar 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.

  • CVE-2020-7853MedMar 24, 2021
    risk 0.36cvss 5.5epss 0.01

    An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker can exploit arbitrary code execution.

  • CVE-2020-12386MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in some Intel(R) Graphics Drivers before version 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-35843MedJan 26, 2021
    risk 0.36cvss 5.5epss 0.01

    FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e.

  • CVE-2018-11007MedJan 11, 2021
    risk 0.36cvss 5.5epss 0.01

    A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.