CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,670)
page 476 of 734| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46760 | Hig | 0.49 | 7.5 | 0.01 | Nov 8, 2023 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions. | ||
| CVE-2023-46770 | Hig | 0.49 | 7.5 | 0.01 | Nov 8, 2023 | Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones. | ||
| CVE-2023-4154 | Hig | 0.49 | 7.5 | 0.01 | Nov 7, 2023 | A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes,… | ||
| CVE-2023-4692 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap… | ||
| CVE-2023-45985 | Hig | 0.49 | 7.5 | 0.01 | Oct 16, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | ||
| CVE-2023-44197 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2023 | An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and… | ||
| CVE-2023-3725 | Hig | 0.49 | 7.6 | 0.01 | Oct 6, 2023 | Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem | ||
| CVE-2023-43868 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function. | ||
| CVE-2023-43867 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanL2TP function. | ||
| CVE-2023-43866 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function. | ||
| CVE-2023-43865 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function. | ||
| CVE-2023-43864 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function. | ||
| CVE-2023-43863 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanDhcpplus function. | ||
| CVE-2023-43862 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function. | ||
| CVE-2023-43861 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function. | ||
| CVE-2023-43860 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2023 | D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function. | ||
| CVE-2023-41307 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-3341 | Hig | 0.49 | 7.5 | 0.03 | Sep 20, 2023 | The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of… | ||
| CVE-2023-40018 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows remote users to trigger out of bounds write by… | ||
| CVE-2023-40308 | Hig | 0.49 | 7.5 | 0.01 | Sep 12, 2023 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any… |
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.
- risk 0.49cvss 7.5epss 0.01
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes,…
- risk 0.49cvss 7.5epss 0.01
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap…
- risk 0.49cvss 7.5epss 0.01
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- risk 0.49cvss 7.5epss 0.01
An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and…
- risk 0.49cvss 7.6epss 0.01
Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanL2TP function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanDhcpplus function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.
- risk 0.49cvss 7.5epss 0.01
Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.03
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of…
- risk 0.49cvss 7.5epss 0.01
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows remote users to trigger out of bounds write by…
- risk 0.49cvss 7.5epss 0.01
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any…