VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 68 of 727
  • CVE-2022-34609CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.

  • CVE-2022-34608CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.

  • CVE-2022-34606CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.

  • CVE-2022-34605CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.

  • CVE-2022-34604CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.

  • CVE-2022-34603CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.

  • CVE-2022-34602CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

  • CVE-2022-34601CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.

  • CVE-2022-34600CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.

  • CVE-2022-34599CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.

  • CVE-2022-20229CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20222CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12…

  • CVE-2022-1737CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a denial-of-service…

  • CVE-2022-33047CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

  • CVE-2022-21744CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction…

  • CVE-2022-20083CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-32386CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

  • CVE-2022-32385CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

  • CVE-2022-32383CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.

  • CVE-2022-34913CriJul 2, 2022
    risk 0.64cvss 9.8epss 0.03

    md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input