VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,654)

page 492 of 733
  • CVE-2022-24145HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.

  • CVE-2022-24143HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

  • CVE-2022-24142HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.

  • CVE-2021-45997HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan,…

  • CVE-2021-45996HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan,…

  • CVE-2021-45995HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.

  • CVE-2021-45994HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the delDhcpIndex parameter.

  • CVE-2021-45993HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.

  • CVE-2021-45992HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.

  • CVE-2021-45991HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.

  • CVE-2021-45989HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.

  • CVE-2021-45988HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.

  • CVE-2022-24030HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

  • CVE-2021-43522HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this…

  • CVE-2020-14107HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.

  • CVE-2021-38783HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.

  • CVE-2021-40028HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2021-40026HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Heap-based buffer overflow vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-40021HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40014HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.