VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 486 of 733
  • CVE-2022-35557HigAug 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

  • CVE-2022-28750HigAug 11, 2022
    risk 0.49cvss 7.5epss 0.02

    Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this…

  • CVE-2022-20247HigAug 11, 2022
    risk 0.49cvss 7.5epss 0.01

    In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2022-20244HigAug 11, 2022
    risk 0.49cvss 7.5epss 0.00

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if more than 100 bluetooth devices have been connected with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-35506HigAug 3, 2022
    risk 0.49cvss 7.5epss 0.01

    TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no limit to the length of program parameters.

  • CVE-2020-14127HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of service.

  • CVE-2022-34759HigJul 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100)…

  • CVE-2022-34742HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-41396HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.

  • CVE-2022-30938HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100…

  • CVE-2022-32053HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

  • CVE-2022-32052HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.

  • CVE-2022-32051HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.

  • CVE-2022-32050HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

  • CVE-2022-32049HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.

  • CVE-2022-32048HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.

  • CVE-2022-32047HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.

  • CVE-2022-32046HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.

  • CVE-2022-32045HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.

  • CVE-2022-32044HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.