VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 702 of 727
  • CVE-2023-4756MedSep 4, 2023
    risk 0.00cvss 5.5epss 0.00

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-4754MedSep 4, 2023
    risk 0.00cvss 5.5epss 0.00

    Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-4751HigSep 3, 2023
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

  • CVE-2023-4738HigSep 2, 2023
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

  • CVE-2022-28072HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.

  • CVE-2022-28069HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0.

  • CVE-2022-28068HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.

  • CVE-2021-32420HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.

  • CVE-2020-22218HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

  • CVE-2023-4322CriAug 14, 2023
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

  • CVE-2023-2905HigAug 9, 2023
    risk 0.00cvss 8.8epss 0.01

    Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…

  • CVE-2023-3812HigJul 24, 2023
    risk 0.00cvss 7.8epss 0.00

    An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges…

  • CVE-2023-3745MedJul 24, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to…

  • CVE-2023-3611HigJul 21, 2023
    risk 0.00cvss 7.8epss 0.00

    An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes…

  • CVE-2021-34119HigJul 18, 2023
    risk 0.00cvss 7.8epss 0.00

    A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.

  • CVE-2023-3138HigJun 28, 2023
    risk 0.00cvss 7.5epss 0.02

    A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array…

  • CVE-2023-3090HigJun 28, 2023
    risk 0.00cvss 7.8epss 0.00

    A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable…

  • CVE-2023-36274HigJun 23, 2023
    risk 0.00cvss 8.8epss 0.01

    LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.

  • CVE-2023-36272HigJun 23, 2023
    risk 0.00cvss 8.8epss 0.01

    LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.

  • CVE-2023-36271HigJun 23, 2023
    risk 0.00cvss 8.8epss 0.01

    LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.