CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 154 of 279
- CVE-2022-38565HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.
- CVE-2022-38566HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.
- CVE-2022-38567HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.
- CVE-2022-38568HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.
- CVE-2022-38569HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.
- CVE-2022-38570HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.
- CVE-2022-38571HIGHCVSS 7.5EG 7.52022-08-28
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.
- CVE-2022-38582MEDIUMCVSS 6.5EG 6.52022-11-04
Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.
- CVE-2022-38671MEDIUMCVSS 5.5EG 5.52022-10-14
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38672MEDIUMCVSS 5.5EG 5.52022-10-14
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38673MEDIUMCVSS 5.5EG 5.52022-10-14
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38675MEDIUMCVSS 5.5EG 5.52023-02-12
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38676MEDIUMCVSS 5.5EG 5.52022-10-14
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38690MEDIUMCVSS 5.5EG 5.52022-10-14
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
- CVE-2022-38701MEDIUMCVSS 6.2EG 3.32022-09-09
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
- CVE-2022-38742HIGHCVSS 8.1EG 9.82022-09-23
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the T…
- CVE-2022-38749MEDIUMCVSS 6.5EG 6.52022-09-05
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
- CVE-2022-38750MEDIUMCVSS 6.5EG 6.52022-09-05
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
- CVE-2022-38751MEDIUMCVSS 6.5EG 6.52022-09-05
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
- CVE-2022-38752MEDIUMCVSS 6.5EG 6.52022-09-05
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.
- CVE-2022-38853MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-38855MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-38856MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-38858MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-38861MEDIUMCVSS 5.5EG 5.52022-09-15
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.
- CVE-2022-38862HIGHCVSS 7.8EG 7.82022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-38863MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
- CVE-2022-38864MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
- CVE-2022-38866MEDIUMCVSS 5.5EG 5.52022-09-15
Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
- CVE-2022-3890CRITICALCVSS 9.6EG 9.62022-11-09
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sev…
- CVE-2022-38932HIGHCVSS 7.8EG 7.82022-09-27
readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.
- CVE-2022-38977HIGHCVSS 7.5EG 7.52022-10-14
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
- CVE-2022-38980CRITICALCVSS 9.8EG 9.82022-10-14
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
- CVE-2022-38986CRITICALCVSS 9.1EG 9.12022-10-14
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting devi…
- CVE-2022-39068MEDIUMCVSS 4.5EG 4.52024-09-18
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.
- CVE-2022-39105MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39106MEDIUMCVSS 5.5EG 5.52022-12-06
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39116MEDIUMCVSS 5.5EG 5.52023-01-04
In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39118MEDIUMCVSS 5.5EG 5.52023-01-04
In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39120MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39121MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39122MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39123MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39124MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39125MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39126MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39127MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39128MEDIUMCVSS 5.5EG 5.52022-10-14
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39129MEDIUMCVSS 5.5EG 5.52022-12-06
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39132MEDIUMCVSS 5.5EG 5.52022-12-06
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →