VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 38 of 727
  • CVE-2023-49404CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

  • CVE-2023-50002CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

  • CVE-2023-50001CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

  • CVE-2023-50000CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

  • CVE-2023-49999CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

  • CVE-2023-49410CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

  • CVE-2023-49403CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

  • CVE-2023-49402CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

  • CVE-2023-49434CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49433CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.

  • CVE-2023-49432CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

  • CVE-2023-49430CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

  • CVE-2023-49426CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2023-49425CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

  • CVE-2023-49424CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2023-48316CriDec 5, 2023
    risk 0.64cvss 9.8epss 0.04

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…

  • CVE-2023-40078CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-45484CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.

  • CVE-2023-45483CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time.

  • CVE-2023-45482CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.