CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 151 of 279
- CVE-2022-36568HIGHCVSS 8.8EG 8.82022-08-31
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.
- CVE-2022-36569HIGHCVSS 8.8EG 8.82022-08-31
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg.
- CVE-2022-36570HIGHCVSS 7.2EG 7.22022-08-31
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
- CVE-2022-36571HIGHCVSS 7.2EG 7.22022-08-31
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
- CVE-2022-3664HIGHCVSS 7.3EG 7.82022-10-26
A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It i…
- CVE-2022-3665HIGHCVSS 7.3EG 7.82022-10-26
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The at…
- CVE-2022-36660CRITICALCVSS 9.8EG 9.82022-09-07
xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().
- CVE-2022-3667HIGHCVSS 7.3EG 7.52022-10-26
A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buf…
- CVE-2022-3670HIGHCVSS 7.3EG 7.82022-10-26
A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack re…
- CVE-2022-36752MEDIUMCVSS 5.5EG 5.52022-07-28
png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.
- CVE-2022-36788HIGHCVSS 8.1EG 8.12023-04-20
A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially-crafted STL file can lead to a heap buffer overflow. An attacker can provide a malic…
- CVE-2022-36841MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36842MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36843MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36844MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36845MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36846MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36858MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36860MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36862MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36863MEDIUMCVSS 4.4EG 7.82022-09-09
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
- CVE-2022-36947CRITICALCVSS 9.8EG 9.82022-08-18
Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.
- CVE-2022-3699HIGHCVSS 7.8EG 9.02023-10-25
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
- CVE-2022-36998MEDIUMCVSS 6.3EG 6.52022-07-28
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client coul…
- CVE-2022-37047HIGHCVSS 7.8EG 7.82022-08-18
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
- CVE-2022-37048HIGHCVSS 7.8EG 7.82022-08-18
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
- CVE-2022-37049HIGHCVSS 7.8EG 7.82022-08-18
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
- CVE-2022-37066CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateDDNS.
- CVE-2022-37067CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanParamsMulti.
- CVE-2022-37068CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateMacCloneFinal.
- CVE-2022-37069CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateSnat.
- CVE-2022-37071CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateOne2One.
- CVE-2022-37072CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanLinkspyMulti.
- CVE-2022-37073CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanModeMulti.
- CVE-2022-37074HIGHCVSS 7.8EG 7.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function switch_debug_info_set.
- CVE-2022-37075HIGHCVSS 7.8EG 7.82022-08-25
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
- CVE-2022-37077HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
- CVE-2022-37078HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
- CVE-2022-37080HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
- CVE-2022-37084HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.
- CVE-2022-37085CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the AddWlanMacList function.
- CVE-2022-37086CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.
- CVE-2022-37087CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetMobileAPInfoById.
- CVE-2022-37088CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAP5GWifiById.
- CVE-2022-37089CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.
- CVE-2022-37090CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID.
- CVE-2022-37091CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.
- CVE-2022-37092CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
- CVE-2022-37093CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.
- CVE-2022-37094CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →