Vulnerabilities > Burrow Wheeler Aligner Project

DATE CVE VULNERABILITY TITLE RISK
2019-04-20 CVE-2019-11371 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Burrow-Wheeler Aligner Project Burrow-Wheeler Aligner 0.7.17
BWA (aka Burrow-Wheeler Aligner) 0.7.17 r1198 has a Buffer Overflow via a long prefix that is mishandled in bns_fasta2bntseq and bns_dump at btnseq.c.
network
low complexity
burrow-wheeler-aligner-project CWE-119
7.5
2019-03-29 CVE-2019-10269 Out-of-bounds Write vulnerability in multiple products
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
network
low complexity
burrow-wheeler-aligner-project canonical CWE-787
critical
9.8