VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 701 of 727
  • CVE-2023-50268MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.00

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-50246MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.01

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-41268MedDec 6, 2023
    risk 0.00cvss 5.3epss 0.01

    Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.

  • CVE-2023-47016HigNov 22, 2023
    risk 0.00cvss 7.5epss 0.01

    radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

  • CVE-2023-48230MedNov 21, 2023
    risk 0.00cvss 5.9epss 0.02

    Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer underrun can be caused by a remote peer. The underrun always writes a constant value that is not…

  • CVE-2023-41101CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer…

  • CVE-2023-47470HigNov 16, 2023
    risk 0.00cvss 7.8epss 0.01

    Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c

  • CVE-2023-48014HigNov 15, 2023
    risk 0.00cvss 7.8epss 0.00

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c.

  • CVE-2023-44398HigNov 6, 2023
    risk 0.00cvss 8.8epss 0.01

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions…

  • CVE-2023-46928MedNov 1, 2023
    risk 0.00cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.

  • CVE-2023-46927MedNov 1, 2023
    risk 0.00cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.

  • CVE-2023-46931MedNov 1, 2023
    risk 0.00cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.

  • CVE-2023-46930MedNov 1, 2023
    risk 0.00cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.

  • CVE-2023-46866MedOct 30, 2023
    risk 0.00cvss 6.5epss 0.01

    In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access array elements at out-of-bounds indexes.

  • CVE-2023-5717HigOct 25, 2023
    risk 0.00cvss 7.8epss 0.01

    A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can…

  • CVE-2023-46602HigOct 23, 2023
    risk 0.00cvss 8.8epss 0.01

    In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in IccXML/IccLibXML/IccUtilXml.cpp in libIccXML.a.

  • CVE-2023-5686HigOct 20, 2023
    risk 0.00cvss 8.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

  • CVE-2023-45863MedOct 14, 2023
    risk 0.00cvss 6.4epss 0.00

    An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a race condition that results in a fill_kobj_path out-of-bounds write.

  • CVE-2023-5344HigOct 2, 2023
    risk 0.00cvss 7.5epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

  • CVE-2023-36184HigSep 8, 2023
    risk 0.00cvss 7.5epss 0.01

    CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.