Vulnerabilities > Out-of-bounds Write

DATE CVE VULNERABILITY TITLE RISK
2022-02-03 CVE-2021-42554 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51.
local
low complexity
insyde siemens CWE-787
7.2
2022-02-03 CVE-2021-43615 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in HddPassword in Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.43.22, and 5.5 before 05.51.22.
local
low complexity
insyde CWE-787
7.2
2022-02-03 CVE-2022-24030 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5.
local
insyde CWE-787
6.9
2022-02-03 CVE-2022-24031 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5.
local
low complexity
insyde CWE-787
7.2
2022-02-03 CVE-2021-43522 Out-of-bounds Write vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08.
local
insyde CWE-787
6.9
2022-02-02 CVE-2020-26208 Out-of-bounds Write vulnerability in Jhead Project Jhead
JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras.
5.8
2022-02-02 CVE-2021-36193 Out-of-bounds Write vulnerability in Fortinet Fortiweb
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
network
low complexity
fortinet CWE-787
6.5
2022-02-01 CVE-2022-24197 Out-of-bounds Write vulnerability in Itextpdf Itext
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
network
low complexity
itextpdf CWE-787
6.5
2022-01-28 CVE-2021-22807 Out-of-bounds Write vulnerability in Schneider-Electric Guicon 2.0
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.
6.8
2022-01-28 CVE-2021-4034 Out-of-bounds Write vulnerability in multiple products
A local privilege escalation vulnerability was found on polkit's pkexec utility.
7.8