VYPR

CWE-788

Access of Memory Location After End of Buffer

BaseIncomplete

Description

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

This typically occurs when a pointer or its index is incremented to a position after the buffer; or when pointer arithmetic results in a position after the buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (147)

page 6 of 8
  • CVE-2021-36000HigAug 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Character Animator version 4.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user.…

  • CVE-2021-35999HigAug 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.0 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of…

  • CVE-2021-35997HigAug 20, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Premiere Pro version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user.…

  • CVE-2021-21093HigApr 15, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the…

  • CVE-2021-21092HigApr 15, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the…

  • CVE-2021-21082HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the…

  • CVE-2020-24415HigOct 20, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction…

  • CVE-2020-24414HigOct 20, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction…

  • CVE-2020-24413HigOct 20, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction…

  • CVE-2020-24412HigOct 20, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction…

  • CVE-2020-9730HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.03

    A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

  • CVE-2020-9729HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.03

    A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

  • CVE-2020-9728HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.03

    A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

  • CVE-2020-9727HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.03

    A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

  • CVE-2023-25506HigApr 22, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information…

  • CVE-2023-0200HigApr 22, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.

  • CVE-2023-0103HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating. This could allow an attacker to cause a denial-of-service condition.

  • CVE-2022-24893HigJun 25, 2022
    risk 0.49cvss 7.5epss 0.01

    ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can…

  • CVE-2021-25661HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels…

  • CVE-2021-25660HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels…