VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 73 of 727
  • CVE-2022-25445CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

  • CVE-2022-25440CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

  • CVE-2022-25439CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

  • CVE-2022-25437CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

  • CVE-2022-25435CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.

  • CVE-2022-25434CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.

  • CVE-2022-25433CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.

  • CVE-2022-25431CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.

  • CVE-2022-25429CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.

  • CVE-2022-25428CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.

  • CVE-2022-25427CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

  • CVE-2022-22635CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4. An application may be able to gain elevated privileges.

  • CVE-2022-22586CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-0982CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client, crafted client requests…

  • CVE-2021-39708CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-26496CriMar 6, 2022
    risk 0.64cvss 9.8epss 0.04

    In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.

  • CVE-2021-46394CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,…

  • CVE-2021-43086CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.01

    ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in…

  • CVE-2022-25418CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

  • CVE-2022-25417CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.