VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 477 of 734
  • CVE-2020-19323HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

  • CVE-2023-30800HigSep 7, 2023
    risk 0.49cvss 7.5epss 0.02

    The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted.…

  • CVE-2023-40915HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

  • CVE-2022-48570HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was…

  • CVE-2022-43358HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.02

    Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).

  • CVE-2022-43357HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.02

    Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

  • CVE-2021-46174HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.

  • CVE-2021-34193HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

  • CVE-2023-39786HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.

  • CVE-2023-39785HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.

  • CVE-2023-39784HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.

  • CVE-2023-40711HigAug 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

  • CVE-2023-39125HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to…

  • CVE-2023-39829HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.

  • CVE-2023-39828HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

  • CVE-2023-39827HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

  • CVE-2023-40296HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.

  • CVE-2023-30699HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

  • CVE-2023-3825HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…

  • CVE-2022-4608HigJul 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500…