VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 489 of 733
  • CVE-2022-27293HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27292HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

  • CVE-2022-27291HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.

  • CVE-2022-27290HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27289HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27288HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27287HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27286HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2021-43521HigApr 8, 2022
    risk 0.49cvss 7.5epss 0.01

    A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.

  • CVE-2022-26953HigApr 6, 2022
    risk 0.49cvss 7.5epss 0.02

    Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body.

  • CVE-2022-26952HigApr 6, 2022
    risk 0.49cvss 7.5epss 0.02

    Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.

  • CVE-2019-12266HigMar 30, 2022
    risk 0.49cvss 7.6epss 0.01

    Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to…

  • CVE-2021-44081HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

  • CVE-2021-3567HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.

  • CVE-2022-22651HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.3. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

  • CVE-2022-25514HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.

  • CVE-2022-26300HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    EOS v2.1.0 was discovered to contain a heap-buffer-overflow via the function txn_test_gen_plugin.

  • CVE-2022-25566HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2022-25561HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

  • CVE-2022-25560HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.