VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 718 of 727
  • CVE-2020-14404MedJun 17, 2020
    risk 0.00cvss 5.4epss 0.02

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.

  • CVE-2020-14403MedJun 17, 2020
    risk 0.00cvss 5.4epss 0.02

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.

  • CVE-2020-14402MedJun 17, 2020
    risk 0.00cvss 5.4epss 0.02

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.

  • CVE-2019-20840HigJun 17, 2020
    risk 0.00cvss 7.5epss 0.03

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.

  • CVE-2020-14147HigJun 15, 2020
    risk 0.00cvss 7.7epss 0.03

    An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox…

  • CVE-2020-13901CriJun 10, 2020
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

  • CVE-2020-10061HigJun 5, 2020
    risk 0.00cvss 8.1epss 0.01

    Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.

  • CVE-2020-13765MedJun 4, 2020
    risk 0.00cvss 5.6epss 0.02

    rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.

  • CVE-2020-13398HigMay 22, 2020
    risk 0.00cvss 8.3epss 0.02

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

  • CVE-2020-10021HigMay 11, 2020
    risk 0.00cvss 8.1epss 0.00

    Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.

  • CVE-2020-12762HigMay 9, 2020
    risk 0.00cvss 7.8epss 0.02

    json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

  • CVE-2020-12659MedMay 5, 2020
    risk 0.00cvss 6.7epss 0.01

    An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.

  • CVE-2020-12653HigMay 5, 2020
    risk 0.00cvss 7.8epss 0.00

    An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.

  • CVE-2020-12654HigMay 5, 2020
    risk 0.00cvss 7.1epss 0.01

    An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.

  • CVE-2020-12284CriApr 28, 2020
    risk 0.00cvss 9.8epss 0.04

    cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.

  • CVE-2020-12268CriApr 27, 2020
    risk 0.00cvss 9.8epss 0.03

    jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

  • CVE-2020-11939CriApr 23, 2020
    risk 0.00cvss 9.8epss 0.03

    In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular nature of the overflow primitive and the ability to control both the contents and…

  • CVE-2019-9183HigApr 23, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflow during 6LoWPAN fragment processing in the face of truncated fragments in os/net/ipv6/sicslowpan.c. This results in accesses of unmapped memory,…

  • CVE-2020-11958HigApr 21, 2020
    risk 0.00cvss 7.8epss 0.02

    re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.

  • CVE-2019-20636MedApr 8, 2020
    risk 0.00cvss 6.7epss 0.00

    In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.