CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 64 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32863 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution. | ||
| CVE-2022-40008 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c. | ||
| CVE-2022-38314 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo. | ||
| CVE-2022-38313 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo. | ||
| CVE-2022-38312 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind. | ||
| CVE-2022-38311 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet. | ||
| CVE-2022-38310 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2022-38309 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2022-36660 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2022 | xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify(). | ||
| CVE-2022-26447 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2022 | In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478. | ||
| CVE-2022-22096 | Cri | 0.64 | 9.8 | 0.00 | Sep 2, 2022 | Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile | ||
| CVE-2022-38555 | Cri | 0.64 | 9.8 | 0.09 | Aug 28, 2022 | Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name. | ||
| CVE-2022-37816 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind. | ||
| CVE-2022-37815 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex. | ||
| CVE-2022-37814 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter. | ||
| CVE-2022-37813 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime. | ||
| CVE-2022-37812 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg. | ||
| CVE-2022-37811 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer. | ||
| CVE-2022-37809 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan. | ||
| CVE-2022-37808 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB. |
- risk 0.64cvss 9.8epss 0.01
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().
- risk 0.64cvss 9.8epss 0.01
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile
- risk 0.64cvss 9.8epss 0.09
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.