CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 46 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40799 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2023 | Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function. | ||
| CVE-2023-40904 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg. | ||
| CVE-2023-40902 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind. | ||
| CVE-2023-40901 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg. | ||
| CVE-2023-40900 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList. | ||
| CVE-2023-40899 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg. | ||
| CVE-2023-40898 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg. | ||
| CVE-2023-40897 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo. | ||
| CVE-2023-40896 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind. | ||
| CVE-2023-40895 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg. | ||
| CVE-2023-40894 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg. | ||
| CVE-2023-40893 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet. | ||
| CVE-2023-40892 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi. | ||
| CVE-2023-40891 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg. | ||
| CVE-2023-4041 | Cri | 0.64 | 9.8 | 0.00 | Aug 23, 2023 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This… | ||
| CVE-2022-48522 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2023 | In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation. | ||
| CVE-2022-48174 | Cri | 0.64 | 9.8 | 0.03 | Aug 22, 2023 | There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. | ||
| CVE-2021-33388 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2023 | dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y | ||
| CVE-2021-32292 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2023 | An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. | ||
| CVE-2023-38961 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c. |
- risk 0.64cvss 9.8epss 0.01
Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi.
- risk 0.64cvss 9.8epss 0.01
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.
- risk 0.64cvss 9.8epss 0.00
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…
- risk 0.64cvss 9.8epss 0.02
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
- risk 0.64cvss 9.8epss 0.03
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.