VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 49 of 727
  • CVE-2023-21250CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-3595CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.05

    Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes…

  • CVE-2023-37712CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.

  • CVE-2023-37711CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

  • CVE-2023-37710CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

  • CVE-2023-37707CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.

  • CVE-2023-37706CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

  • CVE-2023-37705CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.

  • CVE-2023-37704CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

  • CVE-2023-37703CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

  • CVE-2023-37702CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

  • CVE-2023-37701CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-37700CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2020-22336CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.

  • CVE-2023-21066CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-36660CriJun 25, 2023
    risk 0.64cvss 9.8epss 0.01

    The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

  • CVE-2023-34417CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.

  • CVE-2023-34416CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…

  • CVE-2023-32216CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

  • CVE-2023-29531CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects…