VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 64 of 727
  • CVE-2022-32863CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-40008CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.

  • CVE-2022-38314CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

  • CVE-2022-38313CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.

  • CVE-2022-38312CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

  • CVE-2022-38311CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.

  • CVE-2022-38310CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2022-38309CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-36660CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().

  • CVE-2022-26447CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.

  • CVE-2022-22096CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2022-38555CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.09

    Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

  • CVE-2022-37816CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

  • CVE-2022-37815CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.

  • CVE-2022-37814CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

  • CVE-2022-37813CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

  • CVE-2022-37812CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.

  • CVE-2022-37811CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.

  • CVE-2022-37809CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

  • CVE-2022-37808CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.