VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 47 of 727
  • CVE-2023-39751CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.08

    TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.

  • CVE-2023-30187CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

  • CVE-2023-39405CriAug 13, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.

  • CVE-2023-40042CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.

  • CVE-2023-40041CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.

  • CVE-2023-28561CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in QESL while processing payload from external ESL device to firmware.

  • CVE-2022-40510CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.

  • CVE-2023-38940CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2023-38939CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the mit_ssid parameter in the formWrlsafeset function.

  • CVE-2023-38938CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter at /L7Im.

  • CVE-2023-38937CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the…

  • CVE-2023-38936CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the…

  • CVE-2023-38935CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.

  • CVE-2023-38934CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

  • CVE-2023-38933CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

  • CVE-2023-38932CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.

  • CVE-2023-38931CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the…

  • CVE-2023-38930CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-38929CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer.

  • CVE-2023-33375CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices.