VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 44 of 727
  • CVE-2023-43238CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.

  • CVE-2023-43236CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

  • CVE-2023-43235CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

  • CVE-2023-2262CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to…

  • CVE-2023-43203CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.

  • CVE-2023-43201CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.

  • CVE-2023-43200CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.

  • CVE-2023-43199CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.

  • CVE-2023-43198CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.

  • CVE-2023-43197CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.

  • CVE-2023-43196CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.

  • CVE-2023-3935CriSep 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

  • CVE-2023-35681CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40942CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.

  • CVE-2023-28581CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.

  • CVE-2023-28562CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption while handling payloads from remote ESL.

  • CVE-2023-4744CriSep 4, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2023-40848CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858."

  • CVE-2023-40847CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.

  • CVE-2023-40845CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.