CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,905 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 146 of 279
- CVE-2022-34260HIGHCVSS 7.8EG 7.82022-08-11
Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ…
- CVE-2022-34273HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34274HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34275HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34276HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34284HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34286HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34287MEDIUMCVSS 5.5EG 5.52022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information …
- CVE-2022-34289HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an…
- CVE-2022-34290MEDIUMCVSS 5.5EG 5.52022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information …
- CVE-2022-34291MEDIUMCVSS 5.5EG 5.52022-07-12
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information …
- CVE-2022-34400HIGHCVSS 7.1EG 7.12023-02-01
Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.
- CVE-2022-34401HIGHCVSS 7.5EG 7.52023-01-18
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary c…
- CVE-2022-34403HIGHCVSS 7.5EG 8.82023-02-01
Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution…
- CVE-2022-34424HIGHCVSS 7.5EG 7.52022-09-28
Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans.
- CVE-2022-34454MEDIUMCVSS 6.7EG 6.72023-02-10
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.
- CVE-2022-3446HIGHCVSS 8.8EG 8.82022-11-09
Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-34485CRITICALCVSS 9.8EG 9.82022-12-22
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these co…
- CVE-2022-34502MEDIUMCVSS 5.5EG 5.52022-07-22
Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.
- CVE-2022-34503MEDIUMCVSS 6.5EG 6.52022-07-22
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
- CVE-2022-34526MEDIUMCVSS 6.5EG 6.52022-07-29
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
- CVE-2022-34528HIGHCVSS 8.8EG 8.82022-07-29
D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrValue.
- CVE-2022-34599CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.
- CVE-2022-34600CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.
- CVE-2022-34601CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.
- CVE-2022-34602CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.
- CVE-2022-34603CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.
- CVE-2022-34604CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.
- CVE-2022-34605CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.
- CVE-2022-34606CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.
- CVE-2022-34607CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.
- CVE-2022-34608CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.
- CVE-2022-34609CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.
- CVE-2022-34610CRITICALCVSS 9.8EG 9.82022-07-20
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.
- CVE-2022-34667MEDIUMCVSS 4.4EG 4.42022-11-19
NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrup…
- CVE-2022-34671HIGHCVSS 8.5EG 8.82022-12-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.
- CVE-2022-34742HIGHCVSS 7.5EG 7.52022-07-12
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-34748HIGHCVSS 7.8EG 7.82022-07-12
A vulnerability has been identified in Simcenter Femap (All versions < V2022.2). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted X_T files. This could allow an…
- CVE-2022-34759HIGHCVSS 7.5EG 7.52022-07-13
A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Mo…
- CVE-2022-34819CRITICALCVSS 10.0EG 10.02022-07-12
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC…
- CVE-2022-34835CRITICALCVSS 9.8EG 9.82022-06-30
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
- CVE-2022-34884HIGHCVSS 7.2EG 6.52023-01-30
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
- CVE-2022-34886HIGHCVSS 8.8EG 8.82023-10-27
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.
- CVE-2022-3491HIGHCVSS 7.8EG 9.82022-12-03
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- CVE-2022-34913CRITICALCVSS 9.8EG 9.82022-07-02
md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input
- CVE-2022-34927HIGHCVSS 7.8EG 7.82022-08-03
MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.
- CVE-2022-34992HIGHCVSS 7.8EG 7.82022-08-03
Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
- CVE-2022-35007MEDIUMCVSS 6.5EG 6.52022-08-16
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_common_interceptors.inc.
- CVE-2022-35008MEDIUMCVSS 6.5EG 6.52022-08-16
PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp.
- CVE-2022-35010MEDIUMCVSS 6.5EG 6.52022-08-16
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via asan_interceptors_memintrinsics.cpp.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →