VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 659 of 727
  • CVE-2024-12185MedDec 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login Password Handler. The manipulation of the argument Str2 leads to stack-based buffer overflow.…

  • CVE-2024-11262MedNov 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of the component View All Student Marks. The manipulation leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-21979MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

  • CVE-2024-21972MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

  • CVE-2024-0162MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.

  • CVE-2024-26327MedFeb 19, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.

  • CVE-2024-0772MedJan 22, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. Local access is required to…

  • CVE-2024-0771MedJan 21, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack…

  • CVE-2024-21596MedJan 12, 2024
    risk 0.34cvss 5.3epss 0.01

    A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). If an attacker sends a specific BGP UPDATE message to the…

  • CVE-2023-49992MedDec 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.

  • CVE-2023-49991MedDec 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.

  • CVE-2023-32643MedSep 14, 2023
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to…

  • CVE-2023-30666MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

  • CVE-2023-2873MedMay 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. Local…

  • CVE-2023-1646MedMar 26, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to stack-based buffer…

  • CVE-2023-0330MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

  • CVE-2022-42255MedDec 30, 2022
    risk 0.34cvss 5.3epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.

  • CVE-2014-125018MedJun 19, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0. Affected by this issue is the function decode_slice_header. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2014-125010MedJun 18, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch…

  • CVE-2019-25063MedJun 8, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Sricam IP CCTV Camera. It has been classified as critical. Affected is an unknown function of the component Device Viewer. The manipulation leads to memory corruption. Local access is required to approach this attack.