VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 478 of 734
  • CVE-2023-35077HigJul 21, 2023
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.

  • CVE-2023-31998HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.

  • CVE-2023-26597HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and…

  • CVE-2023-24474HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

  • CVE-2023-22435HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

  • CVE-2023-3596HigJul 12, 2023
    risk 0.49cvss 7.5epss 0.04

    Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.

  • CVE-2022-31810HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a stack-based buffer overflow. This could allow an unauthenticated…

  • CVE-2023-34937HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34936HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34935HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34934HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34933HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34932HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34931HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34930HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34929HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34928HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34924HigJun 26, 2023
    risk 0.49cvss 7.5epss 0.01

    H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-32397HigJun 23, 2023
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.

  • CVE-2023-2911HigJun 21, 2023
    risk 0.49cvss 7.5epss 0.02

    If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This…