VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 648 of 727
  • CVE-2019-20160MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c.

  • CVE-2019-8798MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.

  • CVE-2019-8705MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15, tvOS 13. Processing a maliciously crafted movie may result in the disclosure of process memory.

  • CVE-2019-7293MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to read kernel memory.

  • CVE-2019-19797MedDec 15, 2019
    risk 0.36cvss 5.5epss 0.01

    read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

  • CVE-2019-19746MedDec 12, 2019
    risk 0.36cvss 5.5epss 0.01

    make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.

  • CVE-2019-19555MedDec 4, 2019
    risk 0.36cvss 5.5epss 0.01

    read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.

  • CVE-2019-5868MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.01

    Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-5860MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.01

    Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-2336MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-18821MedNov 7, 2019
    risk 0.36cvss 5.5epss 0.00

    Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053.

  • CVE-2019-18820MedNov 7, 2019
    risk 0.36cvss 5.5epss 0.00

    Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

  • CVE-2019-18819MedNov 7, 2019
    risk 0.36cvss 5.5epss 0.00

    Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.

  • CVE-2016-4289MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.01

    A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2.1.19357 application. A specially created long path can lead to a buffer overflow on the stack resulting in code execution. An attacker needs to create path…

  • CVE-2019-16927MedSep 27, 2019
    risk 0.36cvss 5.5epss 0.01

    Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.

  • CVE-2019-14665MedAug 5, 2019
    risk 0.36cvss 5.5epss 0.01

    Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.

  • CVE-2019-14663MedAug 5, 2019
    risk 0.36cvss 5.5epss 0.01

    Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.

  • CVE-2019-14662MedAug 5, 2019
    risk 0.36cvss 5.5epss 0.01

    Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.

  • CVE-2019-14464MedJul 31, 2019
    risk 0.36cvss 5.5epss 0.01

    XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.

  • CVE-2019-14275MedJul 26, 2019
    risk 0.36cvss 5.5epss 0.01

    Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.