Vulnerabilities > Out-of-bounds Write

DATE CVE VULNERABILITY TITLE RISK
2017-02-20 CVE-2016-4671 Out-of-bounds Write vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-787
7.8
2017-02-17 CVE-2016-6870 Out-of-bounds Write vulnerability in Facebook Hhvm
Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
network
low complexity
facebook CWE-787
critical
9.8
2017-02-17 CVE-2016-5044 Out-of-bounds Write vulnerability in Libdwarf Project Libdwarf
The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section.
network
low complexity
libdwarf-project CWE-787
7.5
2017-02-17 CVE-2016-5034 Out-of-bounds Write vulnerability in Libdwarf Project Libdwarf
dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file, related to relocation records.
network
low complexity
libdwarf-project CWE-787
6.5
2017-02-15 CVE-2016-7392 Out-of-bounds Write vulnerability in Autotrace Project Autotrace 0.31.1
Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted bmp image file.
local
low complexity
autotrace-project CWE-787
5.5
2017-02-15 CVE-2016-9560 Out-of-bounds Write vulnerability in multiple products
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.
local
low complexity
jasper-project debian redhat CWE-787
7.8
2017-02-15 CVE-2017-2996 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in Primetime SDK.
network
low complexity
adobe CWE-787
8.8
2017-02-15 CVE-2017-2992 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header.
network
low complexity
adobe CWE-787
8.8
2017-02-15 CVE-2017-2991 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in the h264 codec (related to decompression).
network
low complexity
adobe CWE-787
8.8
2017-02-15 CVE-2017-2990 Out-of-bounds Write vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in the h264 decompression routine.
network
low complexity
adobe CWE-787
8.8