VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 61 of 727
  • CVE-2022-44187CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

  • CVE-2022-44186CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

  • CVE-2022-42058CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-34569CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

  • CVE-2022-43108CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2022-43107CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2022-43106CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

  • CVE-2022-43105CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

  • CVE-2022-43104CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

  • CVE-2022-43103CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.

  • CVE-2022-43102CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

  • CVE-2022-43101CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

  • CVE-2022-42808CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.

  • CVE-2022-40876CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.02

    In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

  • CVE-2022-3386CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.

  • CVE-2022-3385CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.

  • CVE-2022-43003CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

  • CVE-2022-43002CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.

  • CVE-2022-43001CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

  • CVE-2022-43000CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.