CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 648 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20160 | Med | 0.36 | 5.5 | 0.01 | Dec 31, 2019 | An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c. | ||
| CVE-2019-8798 | Med | 0.36 | 5.5 | 0.00 | Dec 18, 2019 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges. | ||
| CVE-2019-8705 | Med | 0.36 | 5.5 | 0.01 | Dec 18, 2019 | A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15, tvOS 13. Processing a maliciously crafted movie may result in the disclosure of process memory. | ||
| CVE-2019-7293 | Med | 0.36 | 5.5 | 0.00 | Dec 18, 2019 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to read kernel memory. | ||
| CVE-2019-19797 | Med | 0.36 | 5.5 | 0.01 | Dec 15, 2019 | read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. | ||
| CVE-2019-19746 | Med | 0.36 | 5.5 | 0.01 | Dec 12, 2019 | make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. | ||
| CVE-2019-19555 | Med | 0.36 | 5.5 | 0.01 | Dec 4, 2019 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. | ||
| CVE-2019-5868 | Med | 0.36 | 5.5 | 0.01 | Nov 25, 2019 | Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | ||
| CVE-2019-5860 | Med | 0.36 | 5.5 | 0.01 | Nov 25, 2019 | Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | ||
| CVE-2019-2336 | Med | 0.36 | 5.5 | 0.00 | Nov 21, 2019 | Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2019-18821 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2019 | Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053. | ||
| CVE-2019-18820 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2019 | Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. | ||
| CVE-2019-18819 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2019 | Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7. | ||
| CVE-2016-4289 | Med | 0.36 | 5.5 | 0.01 | Oct 29, 2019 | A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2.1.19357 application. A specially created long path can lead to a buffer overflow on the stack resulting in code execution. An attacker needs to create path… | ||
| CVE-2019-16927 | Med | 0.36 | 5.5 | 0.01 | Sep 27, 2019 | Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877. | ||
| CVE-2019-14665 | Med | 0.36 | 5.5 | 0.01 | Aug 5, 2019 | Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code. | ||
| CVE-2019-14663 | Med | 0.36 | 5.5 | 0.01 | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code. | ||
| CVE-2019-14662 | Med | 0.36 | 5.5 | 0.01 | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code. | ||
| CVE-2019-14464 | Med | 0.36 | 5.5 | 0.01 | Jul 31, 2019 | XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. | ||
| CVE-2019-14275 | Med | 0.36 | 5.5 | 0.01 | Jul 26, 2019 | Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. |
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c.
- risk 0.36cvss 5.5epss 0.00
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
- risk 0.36cvss 5.5epss 0.01
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15, tvOS 13. Processing a maliciously crafted movie may result in the disclosure of process memory.
- risk 0.36cvss 5.5epss 0.00
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to read kernel memory.
- risk 0.36cvss 5.5epss 0.01
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
- risk 0.36cvss 5.5epss 0.01
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
- risk 0.36cvss 5.5epss 0.01
read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
- risk 0.36cvss 5.5epss 0.01
Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- risk 0.36cvss 5.5epss 0.01
Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- risk 0.36cvss 5.5epss 0.00
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.36cvss 5.5epss 0.00
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053.
- risk 0.36cvss 5.5epss 0.00
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.
- risk 0.36cvss 5.5epss 0.00
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.
- risk 0.36cvss 5.5epss 0.01
A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2.1.19357 application. A specially created long path can lead to a buffer overflow on the stack resulting in code execution. An attacker needs to create path…
- risk 0.36cvss 5.5epss 0.01
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
- risk 0.36cvss 5.5epss 0.01
Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.
- risk 0.36cvss 5.5epss 0.01
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.
- risk 0.36cvss 5.5epss 0.01
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.
- risk 0.36cvss 5.5epss 0.01
XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
- risk 0.36cvss 5.5epss 0.01
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.