VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 54 of 727
  • CVE-2023-26805CriMar 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.

  • CVE-2023-27239CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.

  • CVE-2023-22752CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22751CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-37937CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-auth memory corruption in HPE Serviceguard

  • CVE-2022-46723CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.

  • CVE-2022-26760CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

  • CVE-2023-25233CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-25231CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-24212CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

  • CVE-2021-43529CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.00

    Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with…

  • CVE-2022-48322CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

  • CVE-2022-40514CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.

  • CVE-2022-33279CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.

  • CVE-2022-25729CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in modem due to improper length check while copying into memory

  • CVE-2023-24352CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.

  • CVE-2023-24351CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.

  • CVE-2023-24350CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.

  • CVE-2023-24349CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

  • CVE-2023-24348CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.