VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 14 of 727
  • CVE-2022-30521CriJun 2, 2022
    risk 0.65cvss 9.8epss 0.14

    The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of…

  • CVE-2022-23676CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.22

    A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions;…

  • CVE-2022-29329CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.14

    D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.

  • CVE-2022-29328CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.14

    D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

  • CVE-2022-29322CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.17

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.

  • CVE-2022-25450CriMar 18, 2022
    risk 0.65cvss 9.8epss 0.12

    Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

  • CVE-2022-24995CriMar 10, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2021-46393CriMar 4, 2022
    risk 0.65cvss 9.8epss 0.16

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security…

  • CVE-2022-25414CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.10

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

  • CVE-2022-25074CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25073CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25072CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-24954CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.12

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.

  • CVE-2022-20749CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20712CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.03

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20711CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20710CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20709CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20706CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.06

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20704CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…