VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 476 of 734
  • CVE-2023-46760HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2023-46770HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

  • CVE-2023-4154HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes,…

  • CVE-2023-4692HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap…

  • CVE-2023-45985HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-44197HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and…

  • CVE-2023-3725HigOct 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

  • CVE-2023-43868HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

  • CVE-2023-43867HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanL2TP function.

  • CVE-2023-43866HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

  • CVE-2023-43865HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.

  • CVE-2023-43864HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function.

  • CVE-2023-43863HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanDhcpplus function.

  • CVE-2023-43862HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.

  • CVE-2023-43861HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.

  • CVE-2023-43860HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.

  • CVE-2023-41307HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-3341HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.03

    The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of…

  • CVE-2023-40018HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows remote users to trigger out of bounds write by…

  • CVE-2023-40308HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.01

    SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any…