VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 34 of 727
  • CVE-2024-0244CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and…

  • CVE-2023-6234CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera…

  • CVE-2023-6233CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C…

  • CVE-2023-6232CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary…

  • CVE-2023-6231CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series…

  • CVE-2023-6230CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary…

  • CVE-2023-6229CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C…

  • CVE-2024-24543CriFeb 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.

  • CVE-2024-23978CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.

  • CVE-2024-24561CriFeb 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() function uses a non-literal…

  • CVE-2024-22751CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

  • CVE-2023-51889CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.

  • CVE-2024-22662CriJan 23, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules

  • CVE-2024-22660CriJan 23, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg

  • CVE-2023-6816CriJan 18, 2024
    risk 0.64cvss 9.8epss 0.02

    A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number…

  • CVE-2024-22916CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

  • CVE-2023-49351CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

  • CVE-2023-31488CriJan 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a…

  • CVE-2023-51970CriJan 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

  • CVE-2023-51969CriJan 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.