CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,905 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 145 of 279
- CVE-2022-33108HIGHCVSS 7.8EG 7.82022-06-28
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
- CVE-2022-33183HIGHCVSS 8.8EG 8.82022-10-25
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” co…
- CVE-2022-33184HIGHCVSS 7.8EG 7.82022-10-25
A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute…
- CVE-2022-33185HIGHCVSS 7.8EG 7.82022-10-25
Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows,…
- CVE-2022-33210HIGHCVSS 8.4EG 7.82022-10-19
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto
- CVE-2022-33218HIGHCVSS 8.2EG 7.82023-01-09
Memory corruption in Automotive due to improper input validation.
- CVE-2022-33232CRITICALCVSS 9.3EG 7.82023-02-12
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
- CVE-2022-33233HIGHCVSS 7.8EG 7.82023-02-12
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
- CVE-2022-33234HIGHCVSS 7.3EG 9.82022-11-15
Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-3324HIGHCVSS 7.8EG 7.82022-09-27
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- CVE-2022-33243HIGHCVSS 8.4EG 7.82023-02-12
Memory corruption due to improper access control in Qualcomm IPC.
- CVE-2022-33246MEDIUMCVSS 6.7EG 7.82023-02-12
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.
- CVE-2022-33255HIGHCVSS 8.2EG 6.52023-01-09
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device.
- CVE-2022-33260MEDIUMCVSS 5.9EG 7.82023-03-10
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
- CVE-2022-33264HIGHCVSS 7.9EG 7.92023-06-06
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- CVE-2022-33265HIGHCVSS 7.3EG 9.82023-01-09
Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a single, unassociated device.
- CVE-2022-33267MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in Linux while sending DRM request.
- CVE-2022-33276HIGHCVSS 8.4EG 7.82023-01-09
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
- CVE-2022-33277HIGHCVSS 8.4EG 7.82023-02-12
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
- CVE-2022-33279CRITICALCVSS 9.8EG 9.82023-02-12
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
- CVE-2022-33280HIGHCVSS 7.3EG 8.82023-02-12
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
- CVE-2022-33283HIGHCVSS 8.2EG 6.52023-01-09
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
- CVE-2022-33284HIGHCVSS 8.2EG 6.52023-01-09
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
- CVE-2022-33285HIGHCVSS 7.5EG 6.52023-01-09
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
- CVE-2022-33286HIGHCVSS 7.5EG 6.52023-01-09
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
- CVE-2022-33300HIGHCVSS 8.4EG 7.82023-01-09
Memory corruption in Automotive Android OS due to improper input validation.
- CVE-2022-3349MEDIUMCVSS 6.8EG 6.82022-09-28
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overf…
- CVE-2022-3373HIGHCVSS 8.8EG 8.82022-11-01
Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-33730MEDIUMCVSS 6.8EG 6.82022-08-05
Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.
- CVE-2022-3379HIGHCVSS 7.8EG 7.82022-10-27
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outsid…
- CVE-2022-3385CRITICALCVSS 9.8EG 9.82022-10-27
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
- CVE-2022-3386CRITICALCVSS 9.8EG 9.82022-10-27
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
- CVE-2022-33871MEDIUMCVSS 6.6EG 7.22023-02-16
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `e…
- CVE-2022-33883HIGHCVSS 7.8EG 7.82022-10-03
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vu…
- CVE-2022-33885HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
- CVE-2022-33888HIGHCVSS 7.8EG 7.82022-10-03
A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execu…
- CVE-2022-33889HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.
- CVE-2022-33890HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to cod…
- CVE-2022-3396HIGHCVSS 7.8EG 9.82022-10-06
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
- CVE-2022-33967HIGHCVSS 7.8EG 7.82022-07-20
squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lea…
- CVE-2022-3397HIGHCVSS 7.8EG 9.82022-10-06
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
- CVE-2022-3398HIGHCVSS 7.8EG 9.82022-10-06
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
- CVE-2022-34033HIGHCVSS 7.5EG 7.52022-07-18
HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.
- CVE-2022-34035HIGHCVSS 7.5EG 7.52022-07-18
HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.
- CVE-2022-34038HIGHCVSS 7.5EG 7.52023-08-22
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.
- CVE-2022-3409HIGHCVSS 8.2EG 7.52022-10-27
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled t…
- CVE-2022-34217HIGHCVSS 7.8EG 7.82022-07-15
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2022-34245HIGHCVSS 7.8EG 7.82022-07-15
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…
- CVE-2022-34247HIGHCVSS 7.8EG 7.82022-07-15
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…
- CVE-2022-34251HIGHCVSS 7.8EG 7.82022-07-15
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →