VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 39 of 727
  • CVE-2023-45481CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.

  • CVE-2023-45480CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

  • CVE-2023-45479CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098.

  • CVE-2023-49044CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.

  • CVE-2023-49042CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.

  • CVE-2023-49046CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.

  • CVE-2023-29075CriNov 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2023-29074CriNov 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2023-29073CriNov 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2023-36036HigKEVNov 14, 2023
    risk 0.64cvss 7.8epss 0.17

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2023-45225CriNov 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras  with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the…

  • CVE-2023-43755CriNov 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from…

  • CVE-2023-5941CriNov 8, 2023
    risk 0.64cvss 9.8epss 0.01

    In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an…

  • CVE-2023-47359CriNov 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

  • CVE-2023-33045CriNov 7, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.

  • CVE-2023-22388CriNov 7, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory Corruption in Multi-mode Call Processor while processing bit mask API.

  • CVE-2023-39281CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.00

    A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

  • CVE-2023-46977CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.09

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2023-5731CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119.

  • CVE-2023-5730CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…