VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 709 of 727
  • CVE-2022-29379CriMay 25, 2022
    risk 0.00cvss 9.8epss 0.02

    Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2,…

  • CVE-2022-1785HigMay 19, 2022
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

  • CVE-2022-1733HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

  • CVE-2022-1621HigMay 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-1619HigMay 8, 2022
    risk 0.00cvss 7.8epss 0.03

    Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution

  • CVE-2022-30292CriMay 4, 2022
    risk 0.00cvss 10.0epss 0.04

    Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

  • CVE-2022-27470HigMay 4, 2022
    risk 0.00cvss 7.8epss 0.01

    SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.

  • CVE-2022-27239HigApr 27, 2022
    risk 0.00cvss 7.8epss 0.01

    In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

  • CVE-2022-28085HigApr 27, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).

  • CVE-2022-1437HigApr 22, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

  • CVE-2021-42782MedApr 18, 2022
    risk 0.00cvss 5.3epss 0.03

    Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

  • CVE-2021-42781MedApr 18, 2022
    risk 0.00cvss 5.3epss 0.03

    Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

  • CVE-2022-1383MedApr 18, 2022
    risk 0.00cvss 6.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

  • CVE-2022-1381HigApr 18, 2022
    risk 0.00cvss 7.8epss 0.03

    global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-28044CriApr 15, 2022
    risk 0.00cvss 9.8epss 0.02

    Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

  • CVE-2022-1286CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.01

    heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-24786CriApr 6, 2022
    risk 0.00cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A…

  • CVE-2022-1253CriApr 6, 2022
    risk 0.00cvss 9.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

  • CVE-2022-1240HigApr 6, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable.…

  • CVE-2022-1238HigApr 6, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).