VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 78 of 727
  • CVE-2021-20314CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.03

    Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

  • CVE-2021-38568CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.

  • CVE-2021-33793CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.01

    Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

  • CVE-2021-32943CriAug 10, 2021
    risk 0.64cvss 9.8epss 0.02

    The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

  • CVE-2021-33485CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.01

    CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

  • CVE-2021-22438CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-37164CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur,…

  • CVE-2021-35522CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.04

    A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via…

  • CVE-2021-0276CriJul 15, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading…

  • CVE-2020-11633CriJul 15, 2021
    risk 0.64cvss 9.8epss 0.02

    The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

  • CVE-2021-0515CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.01

    In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-21821CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-22345CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.

  • CVE-2021-35474CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.03

    Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-32988CriJun 29, 2021
    risk 0.64cvss 9.8epss 0.02

    FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

  • CVE-2021-0516CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.02

    In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-27410CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.02

    The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network…

  • CVE-2021-21824CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21795CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can provide a malicious…

  • CVE-2021-0474CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.03

    In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…