VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,670)

page 484 of 734
  • CVE-2022-3602HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.91

    A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to…

  • CVE-2022-43285HigOct 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.

  • CVE-2022-40875HigOct 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

  • CVE-2022-40874HigOct 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

  • CVE-2022-37453HigOct 20, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

  • CVE-2022-42227HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.

  • CVE-2022-43259HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.

  • CVE-2022-38977HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.00

    The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.

  • CVE-2022-42081HigOct 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.

  • CVE-2022-42080HigOct 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter.

  • CVE-2022-42079HigOct 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

  • CVE-2022-39173HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.04

    In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required…

  • CVE-2022-34424HigSep 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans.

  • CVE-2022-40107HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formexeCommand function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40106HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the set_local_time function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40105HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterGet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40104HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40102HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40101HigSep 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-40076HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.