VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 80 of 727
  • CVE-2021-25668CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All…

  • CVE-2021-0254CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.03

    A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution…

  • CVE-2020-28592CriApr 15, 2021
    risk 0.64cvss 9.8epss 0.03

    A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to remote code execution. An attacker can send a malicious packet to trigger this…

  • CVE-2021-28797CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.06

    A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance…

  • CVE-2021-0430CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.03

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-29999CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.

  • CVE-2021-29998CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.

  • CVE-2021-24026CriApr 6, 2021
    risk 0.64cvss 9.8epss 0.01

    A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an…

  • CVE-2021-30072CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

  • CVE-2021-1796CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

  • CVE-2021-1795CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

  • CVE-2020-11227CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2020-11192CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2016-20009CriMar 11, 2021
    risk 0.64cvss 9.8epss 0.02

    A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-0396CriMar 10, 2021
    risk 0.64cvss 9.8epss 0.02

    In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed.…

  • CVE-2021-27804CriMar 2, 2021
    risk 0.64cvss 9.8epss 0.04

    JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.

  • CVE-2020-11283CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-2501CriFeb 17, 2021
    risk 0.64cvss 9.8epss 0.03

    A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance…

  • CVE-2021-3375CriFeb 15, 2021
    risk 0.64cvss 9.8epss 0.04

    ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.

  • CVE-2021-25689CriFeb 11, 2021
    risk 0.64cvss 9.8epss 0.01

    An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute code.