CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 705 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0801 | Med | 0.00 | 6.8 | 0.00 | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available… | ||
| CVE-2023-0800 | Med | 0.00 | 6.8 | 0.00 | Feb 13, 2023 | LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. | ||
| CVE-2023-0819 | Hig | 0.00 | 7.8 | 0.00 | Feb 13, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV. | ||
| CVE-2023-0770 | Hig | 0.00 | 7.8 | 0.00 | Feb 9, 2023 | Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. | ||
| CVE-2023-0760 | Hig | 0.00 | 7.8 | 0.00 | Feb 9, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. | ||
| CVE-2023-23082 | Med | 0.00 | 4.6 | 0.01 | Feb 3, 2023 | A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument. | ||
| CVE-2021-37519 | Med | 0.00 | 5.5 | 0.00 | Feb 3, 2023 | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file. | ||
| CVE-2023-0341 | Hig | 0.00 | 7.8 | 0.01 | Feb 1, 2023 | A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write… | ||
| CVE-2023-23609 | Hig | 0.00 | 8.2 | 0.00 | Jan 26, 2023 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The Bluetooth Low Energy - Logical Link Control and Adaptation… | ||
| CVE-2022-48281 | Med | 0.00 | 5.5 | 0.00 | Jan 23, 2023 | processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image. | ||
| CVE-2023-22741 | Cri | 0.00 | 9.8 | 0.02 | Jan 19, 2023 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in… | ||
| CVE-2023-23456 | Med | 0.00 | 5.3 | 0.00 | Jan 12, 2023 | A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. | ||
| CVE-2023-0054 | Hig | 0.00 | 7.8 | 0.00 | Jan 4, 2023 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145. | ||
| CVE-2022-47942 | Hig | 0.00 | 8.8 | 0.04 | Dec 23, 2022 | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command. | ||
| CVE-2022-47521 | Hig | 0.00 | 7.8 | 0.00 | Dec 18, 2022 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel… | ||
| CVE-2022-47519 | Hig | 0.00 | 7.8 | 0.00 | Dec 18, 2022 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from… | ||
| CVE-2022-47518 | Hig | 0.00 | 7.8 | 0.00 | Dec 18, 2022 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from… | ||
| CVE-2022-3491 | Hig | 0.00 | 7.8 | 0.01 | Dec 3, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. | ||
| CVE-2022-3520 | Cri | 0.00 | 9.8 | 0.01 | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | ||
| CVE-2022-4141 | Hig | 0.00 | 7.8 | 0.00 | Nov 25, 2022 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. |
- risk 0.00cvss 6.8epss 0.00
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available…
- risk 0.00cvss 6.8epss 0.00
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
- risk 0.00cvss 7.8epss 0.00
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
- risk 0.00cvss 4.6epss 0.01
A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.
- risk 0.00cvss 5.5epss 0.00
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
- risk 0.00cvss 7.8epss 0.01
A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write…
- risk 0.00cvss 8.2epss 0.00
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The Bluetooth Low Energy - Logical Link Control and Adaptation…
- risk 0.00cvss 5.5epss 0.00
processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
- risk 0.00cvss 9.8epss 0.02
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in…
- risk 0.00cvss 5.3epss 0.00
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
- risk 0.00cvss 8.8epss 0.04
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel…
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from…
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- risk 0.00cvss 7.8epss 0.00
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.