VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 678 of 727
  • CVE-2024-49739MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-21034MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

  • CVE-2025-54616MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-42971MedJul 8, 2025
    risk 0.26cvss 4.0epss 0.00

    A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could…

  • CVE-2025-20993MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20980MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2024-58116MedApr 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58115MedApr 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-20848MedApr 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2023-6992MedJan 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem…

  • CVE-2022-45126MedJan 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2022-43662MedJan 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2022-41802MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2021-25461MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

  • CVE-2026-45684MedJun 2, 2026
    risk 0.25cvss 4.9epss 0.00

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy…

  • CVE-2026-25790MedMar 17, 2026
    risk 0.25cvss 4.9epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, multiple stack-based buffer overflows exist in the Security Configuration Assessment (SCA) decoder (`wazuh-analysisd`). The use of…

  • CVE-2025-27132LowMay 6, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-24309LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23420LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23240LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.