VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 62 of 727
  • CVE-2022-42998CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.

  • CVE-2022-40984CriOct 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in WTViewerE series WTViewerE 761941 from 1.31 to 1.61 and WTViewerEfree from 1.01 to 1.52 allows an attacker to cause the product to crash by processing a long file name.

  • CVE-2022-43029CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.

  • CVE-2022-43028CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.

  • CVE-2022-43027CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.

  • CVE-2022-43026CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

  • CVE-2022-43025CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.

  • CVE-2022-43024CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-41415CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.

  • CVE-2022-43260CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.

  • CVE-2022-42171CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

  • CVE-2022-42170CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

  • CVE-2022-42169CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

  • CVE-2022-42168CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

  • CVE-2022-42167CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

  • CVE-2022-42166CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

  • CVE-2022-42165CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

  • CVE-2022-42164CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

  • CVE-2022-42163CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

  • CVE-2017-20149CriOct 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute…