CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 153 of 279
- CVE-2022-37816CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- CVE-2022-37817HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- CVE-2022-37818HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- CVE-2022-37819HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.
- CVE-2022-37820HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
- CVE-2022-37821HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.
- CVE-2022-37822HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
- CVE-2022-37823HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.
- CVE-2022-37824HIGHCVSS 7.8EG 7.82022-08-25
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.
- CVE-2022-3784MEDIUMCVSS 6.3EG 7.82022-10-31
A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to…
- CVE-2022-3785MEDIUMCVSS 6.3EG 7.82022-10-31
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The a…
- CVE-2022-37864HIGHCVSS 7.8EG 7.82022-10-11
A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an a…
- CVE-2022-37903HIGHCVSS 7.2EG 8.82022-12-12
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying …
- CVE-2022-37937CRITICALCVSS 9.8EG 9.82023-03-01
Pre-auth memory corruption in HPE Serviceguard
- CVE-2022-37969HIGHCVSS 7.8EG 9.0⚠ KEV2022-09-13
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-38143CRITICALCVSS 9.8EG 9.82022-12-22
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An att…
- CVE-2022-38223HIGHCVSS 7.8EG 7.82022-08-15
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
- CVE-2022-38227HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.
- CVE-2022-38228HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
- CVE-2022-38229HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
- CVE-2022-38231HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.
- CVE-2022-38237HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.
- CVE-2022-38238HIGHCVSS 7.8EG 7.82022-08-16
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.
- CVE-2022-38306HIGHCVSS 7.8EG 5.52022-09-13
LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
- CVE-2022-38309CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- CVE-2022-38310CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- CVE-2022-38311CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
- CVE-2022-38312CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- CVE-2022-38313CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
- CVE-2022-38314CRITICALCVSS 9.8EG 9.82022-09-07
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
- CVE-2022-38401HIGHCVSS 7.8EG 7.82022-09-16
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir…
- CVE-2022-38404HIGHCVSS 7.8EG 7.82022-09-16
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir…
- CVE-2022-38405HIGHCVSS 7.8EG 7.82022-09-16
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir…
- CVE-2022-38411HIGHCVSS 7.8EG 7.82022-09-16
Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue re…
- CVE-2022-38413HIGHCVSS 7.8EG 7.82022-09-16
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…
- CVE-2022-38414HIGHCVSS 7.8EG 7.82022-09-16
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…
- CVE-2022-38415HIGHCVSS 7.8EG 7.82022-09-16
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…
- CVE-2022-38432HIGHCVSS 7.8EG 7.82022-09-16
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue …
- CVE-2022-38433HIGHCVSS 7.8EG 7.82022-09-16
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue …
- CVE-2022-38450HIGHCVSS 7.8EG 7.82022-10-14
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
- CVE-2022-38477HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of th…
- CVE-2022-38478HIGHCVSS 8.8EG 8.82022-12-22
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these cou…
- CVE-2022-38495HIGHCVSS 7.8EG 7.82022-09-13
LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
- CVE-2022-38529HIGHCVSS 7.8EG 7.82022-09-06
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
- CVE-2022-38530HIGHCVSS 7.8EG 7.82022-09-06
GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
- CVE-2022-38533MEDIUMCVSS 5.5EG 5.52022-08-26
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
- CVE-2022-38555CRITICALCVSS 9.8EG 9.82022-08-28
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
- CVE-2022-38562HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.
- CVE-2022-38563HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.
- CVE-2022-38564HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →