CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 152 of 279
- CVE-2022-37095CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.
- CVE-2022-37096CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.
- CVE-2022-37097CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.
- CVE-2022-37098CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.
- CVE-2022-37099CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.
- CVE-2022-37100CRITICALCVSS 9.8EG 9.82022-08-25
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.
- CVE-2022-3715HIGHCVSS 7.8EG 9.82023-01-05
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.
- CVE-2022-37175CRITICALCVSS 9.8EG 9.82022-08-19
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
- CVE-2022-37232CRITICALCVSS 9.8EG 9.82022-09-23
Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.
- CVE-2022-37234HIGHCVSS 7.8EG 7.82022-09-22
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.
- CVE-2022-37235CRITICALCVSS 9.8EG 9.82022-09-23
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat
- CVE-2022-3725MEDIUMCVSS 6.3EG 7.52022-10-27
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
- CVE-2022-37292MEDIUMCVSS 5.5EG 5.52022-08-25
Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /gofo…
- CVE-2022-37325HIGHCVSS 7.5EG 7.52022-12-05
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
- CVE-2022-37331HIGHCVSS 7.3EG 7.32023-07-21
An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a…
- CVE-2022-37354HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37355HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37356HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37357HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37358HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37362HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37364HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37369HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37371HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37372HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-37381HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio…
- CVE-2022-37398HIGHCVSS 7.1EG 8.82022-08-05
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and bel…
- CVE-2022-37415HIGHCVSS 7.8EG 7.82022-08-05
The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
- CVE-2022-37434CRITICALCVSS 9.8EG 9.82022-08-05
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affe…
- CVE-2022-37452CRITICALCVSS 9.8EG 9.82022-08-07
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
- CVE-2022-37453HIGHCVSS 7.5EG 7.52022-10-20
An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.
- CVE-2022-3775HIGHCVSS 7.1EG 7.12022-12-19
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bound…
- CVE-2022-37781HIGHCVSS 7.8EG 7.82022-08-16
fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.inc.
- CVE-2022-37798CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
- CVE-2022-37799CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.
- CVE-2022-37800CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
- CVE-2022-37801CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- CVE-2022-37802CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
- CVE-2022-37803CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
- CVE-2022-37804CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
- CVE-2022-37805CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
- CVE-2022-37806CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
- CVE-2022-37807CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.
- CVE-2022-37808CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
- CVE-2022-37809CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
- CVE-2022-37811CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
- CVE-2022-37812CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.
- CVE-2022-37813CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
- CVE-2022-37814CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.
- CVE-2022-37815CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →