VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 695 of 727
  • CVE-2026-21384MedJul 6, 2026
    risk 0.00cvss 5.3epss 0.00

    Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

  • CVE-2026-21370MedJul 6, 2026
    risk 0.00cvss 5.3epss 0.00

    Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

  • CVE-2026-21369MedJul 6, 2026
    risk 0.00cvss 5.3epss 0.00

    Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

  • CVE-2026-21368MedJul 6, 2026
    risk 0.00cvss 5.3epss 0.00

    Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

  • CVE-2026-40257MedJul 6, 2026
    risk 0.00cvss 5.5epss 0.00

    OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation…

  • CVE-2026-14422HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14420CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-14400HigJul 1, 2026
    risk 0.00cvss 8.3epss 0.00

    Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14397CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14395HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-14392CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14385HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-58592HigJul 1, 2026
    risk 0.00cvss 8.3epss 0.00

    Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to…

  • CVE-2025-23351CriJul 1, 2026
    risk 0.00cvss 9.0epss 0.00

    NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.

  • CVE-2025-23350CriJul 1, 2026
    risk 0.00cvss 9.0epss 0.00

    NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.

  • CVE-2026-7840CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.02

    UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via…

  • CVE-2026-7838HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.01

    UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, the 4-byte network-supplied reasonLen field (type CARD32) is passed as reasonLen+1 to…

  • CVE-2026-7831HigJul 1, 2026
    risk 0.00cvss 7.6epss 0.01

    UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls…

  • CVE-2026-7829HigJul 1, 2026
    risk 0.00cvss 7.2epss 0.01

    UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In repeater/webgui/settings.c:225-272, after strncpy_s copies a rule token into temp1[rule1] (25-byte destination) or temp2/temp3 (16-byte destination), the code…

  • CVE-2026-20461MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed…