CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,906 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 148 of 279
- CVE-2022-35080MEDIUMCVSS 5.5EG 5.52022-10-13
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.
- CVE-2022-35081MEDIUMCVSS 5.5EG 5.52022-10-13
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.
- CVE-2022-35086MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
- CVE-2022-35087MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
- CVE-2022-35088MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swf.c.
- CVE-2022-35090MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.
- CVE-2022-35092MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.
- CVE-2022-35093MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
- CVE-2022-35094MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
- CVE-2022-35095MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.
- CVE-2022-35096MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.
- CVE-2022-35097MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.
- CVE-2022-35098MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.
- CVE-2022-35099MEDIUMCVSS 5.5EG 5.52022-09-23
SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.
- CVE-2022-35101MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memset-vec-unaligned-erms.S.
- CVE-2022-35104MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::reset() at /xpdf/Stream.cc.
- CVE-2022-35105MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via /bin/png2swf+0x552cea.
- CVE-2022-35109MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.
- CVE-2022-35113MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c.
- CVE-2022-3520CRITICALCVSS 9.8EG 9.82022-12-02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- CVE-2022-35217HIGHCVSS 7.8EG 7.82022-08-02
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerabilit…
- CVE-2022-35218MEDIUMCVSS 5.5EG 5.52022-08-02
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt s…
- CVE-2022-35219MEDIUMCVSS 5.5EG 5.52022-08-02
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt se…
- CVE-2022-35222MEDIUMCVSS 6.8EG 6.82022-08-02
HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate…
- CVE-2022-35260MEDIUMCVSS 6.5EG 6.52022-12-05
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a …
- CVE-2022-35407HIGHCVSS 7.8EG 7.82022-11-22
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. …
- CVE-2022-35447MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b04de.
- CVE-2022-35448MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b55af.
- CVE-2022-35449MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b0466.
- CVE-2022-35450MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b84b1.
- CVE-2022-35451MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b03b5.
- CVE-2022-35452MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b0b2c.
- CVE-2022-35453MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6c08a6.
- CVE-2022-35454MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b05aa.
- CVE-2022-35455MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b0d63.
- CVE-2022-35456MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x617087.
- CVE-2022-35458MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b05ce.
- CVE-2022-35459MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e412a.
- CVE-2022-35460MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x61731f.
- CVE-2022-35461MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6c0a32.
- CVE-2022-35462MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6c0bc3.
- CVE-2022-35463MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b0478.
- CVE-2022-35464MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6171b2.
- CVE-2022-35465MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6c0414.
- CVE-2022-35466MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6c0473.
- CVE-2022-35467MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e41b8.
- CVE-2022-35468MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e420d.
- CVE-2022-35470MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x65fc97.
- CVE-2022-35471MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e41b0.
- CVE-2022-35472MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a global overflow via /release-x64/otfccdump+0x718693.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →