CWE-787
Out-of-bounds Write
Description
The product writes data past the end, or before the beginning, of the intended buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (14,531)
page 76 of 727| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28237 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2021 | LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. | ||
| CVE-2021-33274 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80040af8 in /formWlanSetup. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-33271 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_80046EB4 in /formSetPortTr. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-33270 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_800462c4 in /formAdvFirewall. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-33269 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_8004776c in /formVirtualServ. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-33268 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-33267 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80034d60 in /formStaticDHCP. This vulnerability is triggered via a crafted POST request. | ||
| CVE-2021-37022 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2021 | There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated. | ||
| CVE-2021-44143 | Cri | 0.64 | 9.8 | 0.04 | Nov 22, 2021 | A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be… | ||
| CVE-2021-40391 | Cri | 0.64 | 9.8 | 0.03 | Nov 19, 2021 | An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a… | ||
| CVE-2021-37592 | Cri | 0.64 | 9.8 | 0.02 | Nov 19, 2021 | Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments. | ||
| CVE-2021-1975 | Cri | 0.64 | 9.8 | 0.01 | Nov 12, 2021 | Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2020-23878 | Cri | 0.64 | 9.8 | 0.02 | Nov 10, 2021 | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. | ||
| CVE-2020-23877 | Cri | 0.64 | 9.8 | 0.02 | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream. | ||
| CVE-2020-23874 | Cri | 0.64 | 9.8 | 0.02 | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode. | ||
| CVE-2020-23873 | Cri | 0.64 | 9.8 | 0.02 | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump. | ||
| CVE-2021-31886 | Cri | 0.64 | 9.8 | 0.03 | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE… | ||
| CVE-2021-41036 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2021 | In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket. | ||
| CVE-2020-22079 | Cri | 0.64 | 9.8 | 0.04 | Oct 29, 2021 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. | ||
| CVE-2021-21749 | Cri | 0.64 | 9.8 | 0.02 | Oct 20, 2021 | ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code. |
- risk 0.64cvss 9.8epss 0.01
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80040af8 in /formWlanSetup. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_80046EB4 in /formSetPortTr. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_800462c4 in /formAdvFirewall. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_8004776c in /formVirtualServ. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80034d60 in /formStaticDHCP. This vulnerability is triggered via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.
- risk 0.64cvss 9.8epss 0.04
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be…
- risk 0.64cvss 9.8epss 0.03
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a…
- risk 0.64cvss 9.8epss 0.02
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
- risk 0.64cvss 9.8epss 0.01
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.64cvss 9.8epss 0.02
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
- risk 0.64cvss 9.8epss 0.02
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
- risk 0.64cvss 9.8epss 0.02
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
- risk 0.64cvss 9.8epss 0.02
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
- risk 0.64cvss 9.8epss 0.03
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE…
- risk 0.64cvss 9.8epss 0.01
In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.
- risk 0.64cvss 9.8epss 0.04
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
- risk 0.64cvss 9.8epss 0.02
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.