VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 67 of 727
  • CVE-2022-36513CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function edditactionlist.

  • CVE-2022-36511CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditApAdvanceInfo.

  • CVE-2022-37175CriAug 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

  • CVE-2022-36947CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.03

    Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.

  • CVE-2022-2587CriAug 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

  • CVE-2022-20400CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.01

    In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-20237CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.01

    In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-29465CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-28665CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable…

  • CVE-2022-28664CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable…

  • CVE-2022-27631CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-26376CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this…

  • CVE-2022-26009CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger…

  • CVE-2022-25996CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv addTimeGroup functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2022-23919CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23918CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23399CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23103CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger…

  • CVE-2022-32292CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.03

    In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

  • CVE-2022-34610CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.