VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 707 of 727
  • CVE-2022-36041HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when parsing Mach-O files. A user opening a malicious Mach-O file could be affected by this vulnerability, allowing an attacker to…

  • CVE-2022-36040HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from PYC(python) files. A user opening a malicious PYC file could be affected by this vulnerability, allowing an…

  • CVE-2022-36042HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from dyld cache files. A user opening a malicious dyld cache file could be affected by this vulnerability, allowing an…

  • CVE-2022-36039HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to out-of-bounds write when parsing DEX files. A user opening a malicious DEX file could be affected by this vulnerability, allowing an attacker to execute code…

  • CVE-2022-25309MedSep 6, 2022
    risk 0.00cvss 5.5epss 0.00

    A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option,…

  • CVE-2022-25308HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.01

    A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

  • CVE-2020-35530MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

  • CVE-2022-36054MedSep 1, 2022
    risk 0.00cvss 6.8epss 0.01

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in the Contiki-NG operating system (file os/net/ipv6/sicslowpan.c) contains an input function that processes incoming packets and copies them into a packet…

  • CVE-2022-3028HigAug 31, 2022
    risk 0.00cvss 7.0epss 0.00

    A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory…

  • CVE-2022-1354MedAug 31, 2022
    risk 0.00cvss 5.5epss 0.01

    A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.

  • CVE-2022-1115MedAug 29, 2022
    risk 0.00cvss 5.5epss 0.01

    A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.

  • CVE-2022-0367HigAug 29, 2022
    risk 0.00cvss 7.8epss 0.00

    A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.

  • CVE-2022-2991MedAug 25, 2022
    risk 0.00cvss 6.7epss 0.00

    A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to…

  • CVE-2021-3839HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.02

    A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

  • CVE-2022-37452CriAug 7, 2022
    risk 0.00cvss 9.8epss 0.04

    Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

  • CVE-2022-34927HigAug 3, 2022
    risk 0.00cvss 7.8epss 0.00

    MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.

  • CVE-2022-2598MedAug 1, 2022
    risk 0.00cvss 6.5epss 0.01

    Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.

  • CVE-2022-36752MedJul 28, 2022
    risk 0.00cvss 5.5epss 0.00

    png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.

  • CVE-2022-34035HigJul 18, 2022
    risk 0.00cvss 7.5epss 0.02

    HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.

  • CVE-2022-34033HigJul 18, 2022
    risk 0.00cvss 7.5epss 0.02

    HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.