CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 702 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4756 | Med | 0.00 | 5.5 | 0.00 | Sep 4, 2023 | Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-4754 | Med | 0.00 | 5.5 | 0.00 | Sep 4, 2023 | Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-4751 | Hig | 0.00 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-4738 | Hig | 0.00 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2022-28072 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. | ||
| CVE-2022-28069 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-28068 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. | ||
| CVE-2021-32420 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y. | ||
| CVE-2020-22218 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory. | ||
| CVE-2023-4322 | Cri | 0.00 | 9.8 | 0.01 | Aug 14, 2023 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | ||
| CVE-2023-2905 | Hig | 0.00 | 8.8 | 0.01 | Aug 9, 2023 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version… | ||
| CVE-2023-3812 | Hig | 0.00 | 7.8 | 0.00 | Jul 24, 2023 | An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges… | ||
| CVE-2023-3745 | Med | 0.00 | 5.5 | 0.00 | Jul 24, 2023 | A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to… | ||
| CVE-2023-3611 | Hig | 0.00 | 7.8 | 0.00 | Jul 21, 2023 | An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes… | ||
| CVE-2021-34119 | Hig | 0.00 | 7.8 | 0.00 | Jul 18, 2023 | A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. | ||
| CVE-2023-3138 | Hig | 0.00 | 7.5 | 0.02 | Jun 28, 2023 | A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array… | ||
| CVE-2023-3090 | Hig | 0.00 | 7.8 | 0.00 | Jun 28, 2023 | A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable… | ||
| CVE-2023-36274 | Hig | 0.00 | 8.8 | 0.01 | Jun 23, 2023 | LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c. | ||
| CVE-2023-36272 | Hig | 0.00 | 8.8 | 0.01 | Jun 23, 2023 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c. | ||
| CVE-2023-36271 | Hig | 0.00 | 8.8 | 0.01 | Jun 23, 2023 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c. |
- risk 0.00cvss 5.5epss 0.00
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
- risk 0.00cvss 8.8epss 0.01
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…
- risk 0.00cvss 7.8epss 0.00
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges…
- risk 0.00cvss 5.5epss 0.00
A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to…
- risk 0.00cvss 7.8epss 0.00
An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes…
- risk 0.00cvss 7.8epss 0.00
A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.
- risk 0.00cvss 7.5epss 0.02
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array…
- risk 0.00cvss 7.8epss 0.00
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable…
- risk 0.00cvss 8.8epss 0.01
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
- risk 0.00cvss 8.8epss 0.01
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
- risk 0.00cvss 8.8epss 0.01
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.