CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 649 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14274 | Med | 0.36 | 5.5 | 0.02 | Jul 26, 2019 | MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. | ||
| CVE-2019-10974 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2019 | NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code. | ||
| CVE-2019-14250 | Med | 0.36 | 5.5 | 0.02 | Jul 24, 2019 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow. | ||
| CVE-2019-14247 | Med | 0.36 | 5.5 | 0.01 | Jul 24, 2019 | The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file. | ||
| CVE-2019-12551 | Med | 0.36 | 5.5 | 0.02 | Jul 22, 2019 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution. | ||
| CVE-2019-3973 | Med | 0.36 | 5.5 | 0.00 | Jul 17, 2019 | Comodo Antivirus versions 11.0.0.6582 and below are vulnerable to Denial of Service affecting CmdGuard.sys via its filter port "cmdServicePort". A low privileged process can crash CmdVirth.exe to decrease the port's connection count followed by process hollowing a CmdVirth.exe… | ||
| CVE-2019-1010301 | Med | 0.36 | 5.5 | 0.01 | Jul 15, 2019 | jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file. | ||
| CVE-2019-12495 | Med | 0.36 | 5.5 | 0.01 | May 31, 2019 | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-byte out-of-bounds write in the gsym_addr function in x86_64-gen.c. This occurs because tccasm.c mishandles section switches. | ||
| CVE-2019-12298 | Med | 0.36 | 5.5 | 0.01 | May 23, 2019 | Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file. | ||
| CVE-2019-1788 | Med | 0.36 | 5.5 | 0.02 | Apr 8, 2019 | A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is… | ||
| CVE-2019-0161 | Med | 0.36 | 5.5 | 0.00 | Mar 27, 2019 | Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access. | ||
| CVE-2019-6501 | Med | 0.36 | 5.5 | 0.01 | Mar 21, 2019 | In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations. | ||
| CVE-2019-6454 | Med | 0.36 | 5.5 | 0.02 | Mar 21, 2019 | An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a… | ||
| CVE-2019-9754 | Med | 0.36 | 5.5 | 0.01 | Mar 13, 2019 | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byte out of bounds write in the end_macro function in tccpp.c. | ||
| CVE-2019-9209 | Med | 0.36 | 5.5 | 0.01 | Feb 28, 2019 | In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values. | ||
| CVE-2019-8356 | Med | 0.36 | 5.5 | 0.02 | Feb 15, 2019 | An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow. | ||
| CVE-2019-8355 | Med | 0.36 | 5.5 | 0.02 | Feb 15, 2019 | An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channels_start… | ||
| CVE-2019-7664 | Med | 0.36 | 5.5 | 0.01 | Feb 9, 2019 | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash). | ||
| CVE-2019-7559 | Med | 0.36 | 5.5 | 0.01 | Feb 7, 2019 | In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to an out of bounds write in pusht_bfr. | ||
| CVE-2019-6982 | Med | 0.36 | 5.5 | 0.03 | Jan 28, 2019 | An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Write and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of the improper… |
- risk 0.36cvss 5.5epss 0.02
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
- risk 0.36cvss 5.5epss 0.00
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.
- risk 0.36cvss 5.5epss 0.02
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
- risk 0.36cvss 5.5epss 0.01
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
- risk 0.36cvss 5.5epss 0.02
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
- risk 0.36cvss 5.5epss 0.00
Comodo Antivirus versions 11.0.0.6582 and below are vulnerable to Denial of Service affecting CmdGuard.sys via its filter port "cmdServicePort". A low privileged process can crash CmdVirth.exe to decrease the port's connection count followed by process hollowing a CmdVirth.exe…
- risk 0.36cvss 5.5epss 0.01
jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-byte out-of-bounds write in the gsym_addr function in x86_64-gen.c. This occurs because tccasm.c mishandles section switches.
- risk 0.36cvss 5.5epss 0.01
Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file.
- risk 0.36cvss 5.5epss 0.02
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is…
- risk 0.36cvss 5.5epss 0.00
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.01
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
- risk 0.36cvss 5.5epss 0.02
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a…
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byte out of bounds write in the end_macro function in tccpp.c.
- risk 0.36cvss 5.5epss 0.01
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
- risk 0.36cvss 5.5epss 0.02
An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.
- risk 0.36cvss 5.5epss 0.02
An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channels_start…
- risk 0.36cvss 5.5epss 0.01
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
- risk 0.36cvss 5.5epss 0.01
In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to an out of bounds write in pusht_bfr.
- risk 0.36cvss 5.5epss 0.03
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Write and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of the improper…