VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 487 of 733
  • CVE-2022-32043HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.

  • CVE-2022-32041HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.

  • CVE-2022-32040HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.

  • CVE-2022-32039HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.

  • CVE-2022-32037HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.

  • CVE-2022-32036HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.

  • CVE-2022-32034HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.

  • CVE-2022-32033HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.

  • CVE-2022-32031HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetRouteStatic.

  • CVE-2022-32030HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

  • CVE-2022-33087HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.02

    A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2021-33647HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers.

  • CVE-2022-24893HigJun 25, 2022
    risk 0.49cvss 7.5epss 0.01

    ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can…

  • CVE-2022-20209HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-30937HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100…

  • CVE-2021-46814HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2020-14125HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.07

    A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service.

  • CVE-2022-30475HigMay 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/WifiExtraSet request.

  • CVE-2022-30473HigMay 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set

  • CVE-2022-29377HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.