VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 45 of 727
  • CVE-2023-40844CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'

  • CVE-2023-40843CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."

  • CVE-2023-40842CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler."

  • CVE-2023-40841CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"

  • CVE-2023-40840CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat."

  • CVE-2023-41563CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.

  • CVE-2023-41562CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.

  • CVE-2023-41561CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.

  • CVE-2023-41560CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.

  • CVE-2023-41559CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.

  • CVE-2023-41558CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.

  • CVE-2023-41557CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

  • CVE-2023-41556CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.

  • CVE-2023-41555CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.

  • CVE-2023-41554CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.

  • CVE-2023-41553CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.

  • CVE-2023-41552CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.

  • CVE-2023-40890CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR…

  • CVE-2023-40889CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or…

  • CVE-2023-40846CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.