VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 700 of 727
  • CVE-2024-55627MedJan 6, 2025
    risk 0.00cvss 5.9epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an…

  • CVE-2024-38922CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.

  • CVE-2024-11403CriNov 25, 2024
    risk 0.00cvss 9.8epss 0.01

    There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check…

  • CVE-2024-48241MedOct 30, 2024
    risk 0.00cvss 5.5epss 0.00

    An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

  • CVE-2024-45306MedSep 2, 2024
    risk 0.00cvss 4.5epss 0.00

    Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we…

  • CVE-2024-45508CriSep 1, 2024
    risk 0.00cvss 9.8epss 0.01

    HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

  • CVE-2024-43700HigAug 29, 2024
    risk 0.00cvss 7.8epss 0.00

    xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, arbitrary code may be executed on the…

  • CVE-2024-32671CriJul 29, 2024
    risk 0.00cvss 9.8epss 0.00

    Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

  • CVE-2024-0444HigJun 7, 2024
    risk 0.00cvss 8.8epss 0.02

    GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…

  • CVE-2024-34199HigMay 14, 2024
    risk 0.00cvss 8.6epss 0.01

    TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.

  • CVE-2024-32039CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx`…

  • CVE-2024-28231CriMar 20, 2024
    risk 0.00cvss 9.6epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the…

  • CVE-2023-48229HigFeb 14, 2024
    risk 0.00cvss 7.0epss 0.00

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms in the Contiki-NG operating system. The problem is triggered when parsing radio frames in the…

  • CVE-2024-22667HigFeb 5, 2024
    risk 0.00cvss 7.8epss 0.01

    Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.

  • CVE-2024-0962MedJan 27, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the component Configuration File Handler. The manipulation leads to stack-based buffer overflow. The attack may…

  • CVE-2024-0321CriJan 8, 2024
    risk 0.00cvss 9.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2024-22087CriJan 5, 2024
    risk 0.00cvss 9.8epss 0.02

    route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.

  • CVE-2023-7158HigDec 29, 2023
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2023-48704HigDec 22, 2023
    risk 0.00cvss 7.0epss 0.01

    ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-4255MedDec 21, 2023
    risk 0.00cvss 5.5epss 0.00

    An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to…