VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 597 of 731
  • CVE-2023-24132MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3_5g parameter at /goform/WifiBasicSet.

  • CVE-2023-24131MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1_5g parameter at /goform/WifiBasicSet.

  • CVE-2023-24130MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

  • CVE-2023-24129MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.

  • CVE-2023-24128MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.

  • CVE-2023-23781MedFeb 16, 2023
    risk 0.42cvss 6.4epss 0.01

    A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML files.

  • CVE-2021-36489MedFeb 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

  • CVE-2023-0637MedFeb 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is possible to initiate the attack remotely.…

  • CVE-2022-31901MedJan 19, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

  • CVE-2023-22404MedJan 13, 2023
    risk 0.42cvss 6.5epss 0.01

    An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS). iked will crash and restart, and the tunnel…

  • CVE-2022-40961MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

  • CVE-2022-45690HigDec 13, 2022
    risk 0.42cvss 7.5epss 0.01

    A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

  • CVE-2022-45688HigDec 13, 2022
    risk 0.42cvss 7.5epss 0.01

    A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

  • CVE-2022-35260MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.02

    curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will…

  • CVE-2022-37325HigDec 5, 2022
    risk 0.42cvss 7.5epss 0.01

    In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

  • CVE-2022-32621MedDec 5, 2022
    risk 0.42cvss 6.4epss 0.00

    In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310829; Issue ID: ALPS07310829.

  • CVE-2022-43171MedNov 17, 2022
    risk 0.42cvss 6.5epss 0.01

    A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.

  • CVE-2022-32266MedNov 14, 2022
    risk 0.42cvss 6.4epss 0.00

    DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer used by a software SMI…

  • CVE-2022-24938MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2022-28667MedNov 11, 2022
    risk 0.42cvss 6.5epss 0.00

    Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access.