VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 670 of 727
  • CVE-2022-48374MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48373MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48372MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In bootcp service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48240MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48239MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48238MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48237MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-48235MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In MP3 encoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-47486MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-47485MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In modem control device, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

  • CVE-2022-47470MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.

  • CVE-2022-47469MedMay 9, 2023
    risk 0.29cvss 4.4epss 0.00

    In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.

  • CVE-2023-21046MedMar 24, 2023
    risk 0.29cvss 4.4epss 0.00

    In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20956MedMar 24, 2023
    risk 0.29cvss 4.4epss 0.00

    In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12…

  • CVE-2022-34667MedNov 19, 2022
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrupted file and execute cuobjdump against…

  • CVE-2022-36863MedSep 9, 2022
    risk 0.29cvss 4.4epss 0.00

    A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

  • CVE-2022-36862MedSep 9, 2022
    risk 0.29cvss 4.4epss 0.00

    A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

  • CVE-2022-36860MedSep 9, 2022
    risk 0.29cvss 4.4epss 0.00

    A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

  • CVE-2022-36858MedSep 9, 2022
    risk 0.29cvss 4.4epss 0.00

    A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

  • CVE-2022-36846MedSep 9, 2022
    risk 0.29cvss 4.4epss 0.00

    A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.