VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 490 of 733
  • CVE-2022-25558HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.

  • CVE-2022-25557HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the urls parameter.

  • CVE-2022-25556HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

  • CVE-2022-25555HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ntpServer parameter.

  • CVE-2022-25554HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceId parameter.

  • CVE-2022-25553HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsPwd parameter.

  • CVE-2022-25552HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

  • CVE-2022-25551HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsDomain parameter.

  • CVE-2022-25550HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceName parameter.

  • CVE-2022-25549HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsEn parameter.

  • CVE-2022-25548HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter.

  • CVE-2022-25547HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.09

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2021-46408HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter.

  • CVE-2021-40064HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.

  • CVE-2021-40060HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-40058HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-40057HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-45391HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.02

    A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.

  • CVE-2021-22788HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet…

  • CVE-2022-24172HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.