VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 720 of 727
  • CVE-2017-18552HigAug 19, 2019
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.

  • CVE-2017-18551MedAug 19, 2019
    risk 0.00cvss 6.7epss 0.00

    An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.

  • CVE-2019-15148MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.01

    GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c.

  • CVE-2019-13221HigAug 15, 2019
    risk 0.00cvss 7.8epss 0.01

    A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.

  • CVE-2019-13217HigAug 15, 2019
    risk 0.00cvss 7.8epss 0.02

    A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.

  • CVE-2019-14934HigAug 11, 2019
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.

  • CVE-2019-14495CriAug 1, 2019
    risk 0.00cvss 9.8epss 0.02

    webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.

  • CVE-2019-13568HigJul 31, 2019
    risk 0.00cvss 8.8epss 0.02

    CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.

  • CVE-2019-14323HigJul 28, 2019
    risk 0.00cvss 7.5epss 0.02

    SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte. This results in a crash of the server, but only when strict stack checking is enabled. This is caused by an off-by-one error in ssdp_recv in ssdpd.c.

  • CVE-2019-11921CriJul 25, 2019
    risk 0.00cvss 9.8epss 0.02

    An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.

  • CVE-2019-3570CriJul 18, 2019
    risk 0.00cvss 9.8epss 0.02

    Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would…

  • CVE-2019-11360MedJul 12, 2019
    risk 0.00cvss 4.2epss 0.02

    A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.

  • CVE-2019-13308HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.

  • CVE-2019-13307HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.

  • CVE-2019-13306HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.

  • CVE-2019-13305HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

  • CVE-2019-13304HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.

  • CVE-2019-13300HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

  • CVE-2019-13298HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.

  • CVE-2019-12817HigJun 25, 2019
    risk 0.00cvss 7.0epss 0.00

    arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.