VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 37 of 727
  • CVE-2023-50988CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.

  • CVE-2023-50987CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.

  • CVE-2023-50986CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.

  • CVE-2023-50985CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.

  • CVE-2023-50984CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.

  • CVE-2023-46260CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.10

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46258CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.07

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46224CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.07

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46223CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.07

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46222CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.07

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46221CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.07

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-50965CriDec 17, 2023
    risk 0.64cvss 9.8epss 0.02

    In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based buffer overflow and potentially remote code execution via a long URI.

  • CVE-2023-49418CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

  • CVE-2023-49417CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

  • CVE-2023-46932CriDec 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.

  • CVE-2023-48423CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.00

    In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-49007CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.09

    In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

  • CVE-2023-49411CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

  • CVE-2023-49408CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

  • CVE-2023-49405CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.