VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 705 of 727
  • CVE-2023-0801MedFeb 13, 2023
    risk 0.00cvss 6.8epss 0.00

    LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available…

  • CVE-2023-0800MedFeb 13, 2023
    risk 0.00cvss 6.8epss 0.00

    LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

  • CVE-2023-0819HigFeb 13, 2023
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.

  • CVE-2023-0770HigFeb 9, 2023
    risk 0.00cvss 7.8epss 0.00

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.

  • CVE-2023-0760HigFeb 9, 2023
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.

  • CVE-2023-23082MedFeb 3, 2023
    risk 0.00cvss 4.6epss 0.01

    A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.

  • CVE-2021-37519MedFeb 3, 2023
    risk 0.00cvss 5.5epss 0.00

    Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.

  • CVE-2023-0341HigFeb 1, 2023
    risk 0.00cvss 7.8epss 0.01

    A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write…

  • CVE-2023-23609HigJan 26, 2023
    risk 0.00cvss 8.2epss 0.00

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The Bluetooth Low Energy - Logical Link Control and Adaptation…

  • CVE-2022-48281MedJan 23, 2023
    risk 0.00cvss 5.5epss 0.00

    processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.

  • CVE-2023-22741CriJan 19, 2023
    risk 0.00cvss 9.8epss 0.02

    Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in…

  • CVE-2023-23456MedJan 12, 2023
    risk 0.00cvss 5.3epss 0.00

    A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

  • CVE-2023-0054HigJan 4, 2023
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

  • CVE-2022-47942HigDec 23, 2022
    risk 0.00cvss 8.8epss 0.04

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

  • CVE-2022-47521HigDec 18, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel…

  • CVE-2022-47519HigDec 18, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from…

  • CVE-2022-47518HigDec 18, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from…

  • CVE-2022-3491HigDec 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

  • CVE-2022-3520CriDec 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

  • CVE-2022-4141HigNov 25, 2022
    risk 0.00cvss 7.8epss 0.00

    Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.