CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 144 of 279
- CVE-2022-32635HIGHCVSS 7.8EG 7.82023-01-03
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2022-32636MEDIUMCVSS 6.7EG 6.72023-01-03
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS075…
- CVE-2022-32637MEDIUMCVSS 6.7EG 6.72023-01-03
In hevc decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL…
- CVE-2022-32640MEDIUMCVSS 6.7EG 6.72023-01-03
In meta wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2022-32646MEDIUMCVSS 6.7EG 6.72023-01-03
In gpu drm, there is a possible stack overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363501…
- CVE-2022-32647MEDIUMCVSS 6.7EG 6.72023-01-03
In ccu, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0755…
- CVE-2022-32787HIGHCVSS 8.8EG 8.82022-09-23
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing mal…
- CVE-2022-32792HIGHCVSS 8.8EG 8.82022-09-23
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to ar…
- CVE-2022-32793HIGHCVSS 7.5EG 7.52022-08-24
Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.
- CVE-2022-32796HIGHCVSS 7.8EG 7.82022-09-23
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32798HIGHCVSS 7.8EG 7.82022-09-23
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. An app may be able to gain elevated privileges.
- CVE-2022-32810HIGHCVSS 7.8EG 7.82022-08-24
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32812HIGHCVSS 7.8EG 7.82022-08-24
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32813HIGHCVSS 7.8EG 7.82022-08-24
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may b…
- CVE-2022-32815HIGHCVSS 7.8EG 7.82022-09-23
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may b…
- CVE-2022-32820HIGHCVSS 7.8EG 7.82022-09-23
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be…
- CVE-2022-32821HIGHCVSS 7.8EG 7.82022-09-23
A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32827MEDIUMCVSS 5.5EG 5.52022-11-01
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.
- CVE-2022-32837HIGHCVSS 7.8EG 7.82022-08-24
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to cause unexpected system termination or write kernel memory.
- CVE-2022-32843HIGHCVSS 7.1EG 7.12022-09-23
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted Postscript file may result in u…
- CVE-2022-32860HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32863CRITICALCVSS 9.8EG 9.82022-09-20
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2022-32865HIGHCVSS 7.8EG 7.82022-11-01
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32866HIGHCVSS 7.8EG 7.82022-11-01
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32885HIGHCVSS 8.8EG 8.82023-05-08
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2022-32886HIGHCVSS 8.8EG 8.82022-09-20
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2022-32888HIGHCVSS 8.8EG 8.82022-11-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafte…
- CVE-2022-32893HIGHCVSS 8.8EG 9.0⚠ KEV2022-08-24
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code exec…
- CVE-2022-32894HIGHCVSS 7.8EG 9.0⚠ KEV2022-08-24
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is awa…
- CVE-2022-32897HIGHCVSS 7.8EG 7.82024-06-10
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.
- CVE-2022-32908HIGHCVSS 7.8EG 7.82022-09-20
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.
- CVE-2022-32911HIGHCVSS 7.8EG 7.82022-09-20
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32917HIGHCVSS 7.8EG 9.0⚠ KEV2022-09-20
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aw…
- CVE-2022-32925HIGHCVSS 7.1EG 7.12022-11-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.
- CVE-2022-32932HIGHCVSS 7.8EG 7.82022-11-01
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32944HIGHCVSS 7.8EG 7.82022-11-01
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An …
- CVE-2022-32947HIGHCVSS 7.8EG 7.82022-11-01
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32959MEDIUMCVSS 6.8EG 6.82022-07-20
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for OS information. An unauthenticated physical attacker can ex…
- CVE-2022-3296HIGHCVSS 7.8EG 7.82022-09-25
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- CVE-2022-32960MEDIUMCVSS 6.8EG 6.82022-07-20
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for card number. An unauthenticated physical attacker can explo…
- CVE-2022-32961MEDIUMCVSS 6.8EG 6.82022-07-20
HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can…
- CVE-2022-33007HIGHCVSS 8.8EG 8.82022-06-27
TRENDnet Wi-Fi routers TEW751DR v1.03 and TEW-752DRU v1.03 were discovered to contain a stack overflow via the function genacgi_main.
- CVE-2022-33026HIGHCVSS 7.8EG 7.82022-06-23
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
- CVE-2022-33028HIGHCVSS 7.8EG 7.82022-06-23
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
- CVE-2022-33032HIGHCVSS 7.8EG 7.82022-06-23
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
- CVE-2022-33034HIGHCVSS 7.8EG 7.82022-06-23
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
- CVE-2022-33047CRITICALCVSS 9.8EG 9.82022-07-06
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
- CVE-2022-33087HIGHCVSS 7.5EG 7.52022-06-30
A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
- CVE-2022-33099HIGHCVSS 7.5EG 7.52022-07-01
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
- CVE-2022-33103HIGHCVSS 7.8EG 7.82022-07-01
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →