VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 69 of 727
  • CVE-2022-32324CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.01

    PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc.

  • CVE-2022-32032CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.

  • CVE-2022-34835CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.02

    In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

  • CVE-2022-29496CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-20825CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service…

  • CVE-2022-20140CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.09

    In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20127CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.07

    In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-40212CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.02

    An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service.

  • CVE-2021-30341CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-40036CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.

  • CVE-2021-37404CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2022-30926CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /goform/aspForm.

  • CVE-2022-30925CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddMacList parameter at /goform/aspForm.

  • CVE-2022-30924CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetAPWifiorLedInfoById parameter at /goform/aspForm.

  • CVE-2022-30923CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTimingtimeWifiAndLed parameter at /goform/aspForm.

  • CVE-2022-30922CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditWlanMacList parameter at /goform/aspForm.

  • CVE-2022-30921CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetMobileAPInfoById parameter at /goform/aspForm.

  • CVE-2022-30920CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID parameter at /goform/aspForm.

  • CVE-2022-30919CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.

  • CVE-2022-30918CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnet parameter at /goform/aspForm.