VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 481 of 734
  • CVE-2023-27077HigMar 23, 2023
    risk 0.49cvss 7.5epss 0.02

    Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package.

  • CVE-2023-25281HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp.

  • CVE-2023-26073HigMar 13, 2023
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to…

  • CVE-2023-26074HigMar 13, 2023
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to…

  • CVE-2023-26072HigMar 13, 2023
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to…

  • CVE-2023-25283HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.

  • CVE-2023-23519HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Processing an image may lead to a denial-of-service.

  • CVE-2021-37501HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.02

    Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.

  • CVE-2021-36493HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

  • CVE-2023-22842HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. …

  • CVE-2023-0618HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in TRENDnet TEW-652BRP 3.04B01. It has been declared as critical. This vulnerability affects unknown code of the file cfg_op.ccp of the component Web Service. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit…

  • CVE-2022-34403HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM.

  • CVE-2022-34401HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.

  • CVE-2006-20001HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.04

    A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

  • CVE-2023-22415HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all MX Series and SRX Series platform, when H.323 ALG is enabled and specific H.323 packets are received…

  • CVE-2023-22411HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On SRX Series devices using Unified Policies with IPv6, when a specific IPv6 packet goes…

  • CVE-2022-46449HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2022-33286HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.

  • CVE-2022-33285HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.

  • CVE-2022-47116HigDec 30, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.