VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 71 of 727
  • CVE-2022-29393CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.

  • CVE-2022-29392CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.

  • CVE-2022-29391CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.

  • CVE-2022-29327CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.

  • CVE-2022-29326CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

  • CVE-2022-29325CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

  • CVE-2022-29324CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

  • CVE-2022-29323CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

  • CVE-2022-29321CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

  • CVE-2022-28082CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

  • CVE-2022-28561CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.10

    There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-28560CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-29077CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.

  • CVE-2022-27404CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.03

    FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

  • CVE-2022-28711CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.02

    A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177cb9. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-26507CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825,…

  • CVE-2022-27022CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.

  • CVE-2022-27016CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

  • CVE-2021-32976CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.

  • CVE-2021-43722CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.