VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 646 of 727
  • CVE-2020-26519MedOct 2, 2020
    risk 0.36cvss 5.5epss 0.01

    Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.

  • CVE-2020-25600MedSep 23, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness)…

  • CVE-2020-14390MedSep 18, 2020
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

  • CVE-2020-0385MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.01

    In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0384MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.01

    In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0383MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.01

    In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-3621MedSep 8, 2020
    risk 0.36cvss 5.5epss 0.00

    u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer…

  • CVE-2020-24863MedSep 3, 2020
    risk 0.36cvss 5.5epss 0.01

    A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction…

  • CVE-2020-1379MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.03

    A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are…

  • CVE-2020-8230MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.00

    A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.

  • CVE-2020-8679MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in Kernel Mode Driver for some Intel(R) Graphics Drivers before version 26.20.100.7755 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-17538MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16309MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.

  • CVE-2020-16308MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16305MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16304MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.

  • CVE-2020-16300MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16297MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16296MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16292MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.