Vulnerabilities > Out-of-bounds Write

DATE CVE VULNERABILITY TITLE RISK
2017-10-16 CVE-2015-7504 Out-of-bounds Write vulnerability in multiple products
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
local
low complexity
qemu xen debian CWE-787
8.8
2017-10-16 CVE-2017-15289 Out-of-bounds Write vulnerability in Qemu
The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.
local
low complexity
qemu CWE-787
6.0
2017-10-16 CVE-2017-15303 Out-of-bounds Write vulnerability in Cpuid Cpu-Z 1.42
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).
local
low complexity
cpuid CWE-787
7.8
2017-10-11 CVE-2017-2887 Out-of-bounds Write vulnerability in multiple products
An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1.
network
low complexity
libsdl debian CWE-787
8.8
2017-10-10 CVE-2017-11046 Out-of-bounds Write vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is called, a kernel out-of-bounds write can potentially occur.
local
low complexity
google CWE-787
7.8
2017-10-05 CVE-2017-1000111 Out-of-bounds Write vulnerability in multiple products
Linux kernel: heap out-of-bounds in AF_PACKET sockets.
local
low complexity
linux redhat debian CWE-787
7.8
2017-10-04 CVE-2017-14491 Out-of-bounds Write vulnerability in multiple products
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
9.8
2017-10-04 CVE-2017-12166 Out-of-bounds Write vulnerability in multiple products
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
network
low complexity
openvpn debian CWE-787
critical
9.8
2017-09-25 CVE-2015-5237 Out-of-bounds Write vulnerability in Google Protobuf
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
network
low complexity
google CWE-787
8.8
2017-09-21 CVE-2017-14648 Out-of-bounds Write vulnerability in Bladeenc 0.94.2
A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2.
network
low complexity
bladeenc CWE-787
critical
9.8