VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 485 of 733
  • CVE-2020-36601HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.

  • CVE-2020-36600HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2022-26860HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.

  • CVE-2022-2043HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive.

  • CVE-2022-38571HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.

  • CVE-2022-38570HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.

  • CVE-2022-38569HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.

  • CVE-2022-38568HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.

  • CVE-2022-38567HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.

  • CVE-2022-38566HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.

  • CVE-2022-38565HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.

  • CVE-2022-38564HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.

  • CVE-2022-38563HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.

  • CVE-2022-38562HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.

  • CVE-2022-32793HigAug 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.

  • CVE-2022-25903HigAug 24, 2022
    risk 0.49cvss 7.5epss 0.01

    The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.

  • CVE-2022-2831HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.

  • CVE-2022-35561HigAug 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

  • CVE-2022-35560HigAug 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

  • CVE-2022-35558HigAug 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.