CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 720 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18552 | Hig | 0.00 | 7.8 | 0.00 | Aug 19, 2019 | An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency. | ||
| CVE-2017-18551 | Med | 0.00 | 6.7 | 0.00 | Aug 19, 2019 | An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated. | ||
| CVE-2019-15148 | Med | 0.00 | 6.5 | 0.01 | Aug 18, 2019 | GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c. | ||
| CVE-2019-13221 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2019 | A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | ||
| CVE-2019-13217 | Hig | 0.00 | 7.8 | 0.02 | Aug 15, 2019 | A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | ||
| CVE-2019-14934 | Hig | 0.00 | 7.8 | 0.01 | Aug 11, 2019 | An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write. | ||
| CVE-2019-14495 | Cri | 0.00 | 9.8 | 0.02 | Aug 1, 2019 | webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface. | ||
| CVE-2019-13568 | Hig | 0.00 | 8.8 | 0.02 | Jul 31, 2019 | CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image. | ||
| CVE-2019-14323 | Hig | 0.00 | 7.5 | 0.02 | Jul 28, 2019 | SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte. This results in a crash of the server, but only when strict stack checking is enabled. This is caused by an off-by-one error in ssdp_recv in ssdpd.c. | ||
| CVE-2019-11921 | Cri | 0.00 | 9.8 | 0.02 | Jul 25, 2019 | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00. | ||
| CVE-2019-3570 | Cri | 0.00 | 9.8 | 0.02 | Jul 18, 2019 | Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would… | ||
| CVE-2019-11360 | Med | 0.00 | 4.2 | 0.02 | Jul 12, 2019 | A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c. | ||
| CVE-2019-13308 | Hig | 0.00 | 8.8 | 0.03 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage. | ||
| CVE-2019-13307 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows. | ||
| CVE-2019-13306 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors. | ||
| CVE-2019-13305 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error. | ||
| CVE-2019-13304 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment. | ||
| CVE-2019-13300 | Hig | 0.00 | 8.8 | 0.03 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns. | ||
| CVE-2019-13298 | Hig | 0.00 | 8.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error. | ||
| CVE-2019-12817 | Hig | 0.00 | 7.0 | 0.00 | Jun 25, 2019 | arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected. |
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.
- risk 0.00cvss 6.7epss 0.00
An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.
- risk 0.00cvss 6.5epss 0.01
GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c.
- risk 0.00cvss 7.8epss 0.01
A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
- risk 0.00cvss 7.8epss 0.02
A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
- risk 0.00cvss 7.8epss 0.01
An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.
- risk 0.00cvss 9.8epss 0.02
webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.
- risk 0.00cvss 8.8epss 0.02
CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.
- risk 0.00cvss 7.5epss 0.02
SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte. This results in a crash of the server, but only when strict stack checking is enabled. This is caused by an off-by-one error in ssdp_recv in ssdpd.c.
- risk 0.00cvss 9.8epss 0.02
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
- risk 0.00cvss 9.8epss 0.02
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would…
- risk 0.00cvss 4.2epss 0.02
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
- risk 0.00cvss 8.8epss 0.03
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
- risk 0.00cvss 8.8epss 0.03
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
- risk 0.00cvss 8.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.
- risk 0.00cvss 7.0epss 0.00
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.