VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 475 of 734
  • CVE-2023-46803HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.04

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

  • CVE-2023-3430HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash,…

  • CVE-2023-46284HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions),…

  • CVE-2023-49355HigDec 11, 2023
    risk 0.49cvss 7.5epss 0.01

    decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

  • CVE-2023-49800HigDec 9, 2023
    risk 0.49cvss 7.5epss 0.01

    `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow.…

  • CVE-2023-48403HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with no additional execution…

  • CVE-2023-48964HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.

  • CVE-2023-48963HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.

  • CVE-2023-48945HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-49047HigNov 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.

  • CVE-2022-44010HigNov 23, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This does not require authentication. The…

  • CVE-2023-48105HigNov 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.

  • CVE-2023-48111HigNov 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

  • CVE-2023-48110HigNov 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

  • CVE-2023-48109HigNov 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

  • CVE-2023-46772HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vulnerability may cause errors in reading file data.

  • CVE-2023-46767HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-46766HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-46762HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-46761HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.