VYPR

CWE-788

Access of Memory Location After End of Buffer

BaseIncomplete

Description

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

This typically occurs when a pointer or its index is incremented to a position after the buffer; or when pointer arithmetic results in a position after the buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (147)

page 1 of 8
  • CVE-2021-27384CriMay 12, 2021
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels…

  • CVE-2019-8280CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.04

    UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This attack appear to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.

  • CVE-2019-8266CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.03

    UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnection::Copybuffer function in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity.…

  • CVE-2019-8265CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.03

    UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities…

  • CVE-2019-8264CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.03

    UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.

  • CVE-2021-21105HigSep 8, 2021
    risk 0.58cvss 8.8epss 0.06

    Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of…

  • CVE-2021-21104HigSep 8, 2021
    risk 0.58cvss 8.8epss 0.05

    Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of the current user. Exploitation of this…

  • CVE-2024-20402HigOct 23, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service…

  • CVE-2024-20330HigOct 23, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause the Snort detection…

  • CVE-2023-22297HigMay 10, 2023
    risk 0.53cvss 8.2epss 0.00

    Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

  • CVE-2020-9731HigSep 10, 2020
    risk 0.52cvss 7.8epss 0.11

    A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

  • CVE-2024-27828HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2024-27829HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2021-42735HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

  • CVE-2021-42732HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Access of Memory Location After End of Buffer (CWE-788)

  • CVE-2021-40727HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Access of Memory Location After End of Buffer (CWE-788

  • CVE-2021-42730HigMar 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PSD file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42729HigMar 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42724HigMar 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42527HigMar 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to…