VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 63 of 727
  • CVE-2022-41578CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.

  • CVE-2022-38980CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

  • CVE-2022-41522CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

  • CVE-2016-2338CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.05

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can…

  • CVE-2022-40942CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.08

    Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

  • CVE-2022-40868CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

  • CVE-2022-40867CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

  • CVE-2022-40866CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

  • CVE-2022-40854CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

  • CVE-2022-40851CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

  • CVE-2022-40869CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

  • CVE-2022-40865CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/

  • CVE-2022-40864CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet

  • CVE-2022-40862CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

  • CVE-2022-40860CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

  • CVE-2022-40853CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

  • CVE-2022-37235CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

  • CVE-2022-37232CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

  • CVE-2022-31937CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

  • CVE-2022-41220CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input