Vulnerabilities > Out-of-bounds Write

DATE CVE VULNERABILITY TITLE RISK
2019-10-28 CVE-2019-11043 Out-of-bounds Write vulnerability in multiple products
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
network
low complexity
php canonical debian fedoraproject tenable redhat CWE-787
critical
9.8
2019-10-25 CVE-2019-17145 Out-of-bounds Write vulnerability in Foxitsoftware Phantompdf 9.6.0.25114
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114.
network
low complexity
foxitsoftware CWE-787
8.8
2019-10-25 CVE-2019-17144 Out-of-bounds Write vulnerability in Foxitsoftware Phantompdf 9.6.0.25114
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114.
network
low complexity
foxitsoftware CWE-787
8.8
2019-10-25 CVE-2019-17139 Out-of-bounds Write vulnerability in Foxitsoftware Foxit Reader
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723.
network
low complexity
foxitsoftware CWE-787
8.8
2019-10-25 CVE-2019-16265 Out-of-bounds Write vulnerability in Codesys and ENI Server
CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.
network
low complexity
codesys CWE-787
critical
9.8
2019-10-23 CVE-2019-11933 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.
network
low complexity
libpl-droidsonroids-gif-project whatsapp CWE-787
critical
9.8
2019-10-22 CVE-2019-17424 Out-of-bounds Write vulnerability in Nipper-Ng Project Nipper-Ng 0.11.10
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.
local
low complexity
nipper-ng-project CWE-787
7.8
2019-10-21 CVE-2019-18224 Out-of-bounds Write vulnerability in GNU Libidn2
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
network
low complexity
gnu CWE-787
critical
9.8
2019-10-21 CVE-2019-18218 Out-of-bounds Write vulnerability in multiple products
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
7.8
2019-10-18 CVE-2019-13545 Out-of-bounds Write vulnerability in Hornerautomation Cscape
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
local
low complexity
hornerautomation CWE-787
7.8