CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 156 of 279
- CVE-2022-40149MEDIUMCVSS 6.5EG 6.52022-09-16
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow…
- CVE-2022-40151MEDIUMCVSS 6.5EG 6.52022-09-16
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect ma…
- CVE-2022-40152MEDIUMCVSS 6.5EG 6.52022-09-16
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack…
- CVE-2022-40159MEDIUMCVSS 6.5EG 6.52022-10-06
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocati…
- CVE-2022-40160MEDIUMCVSS 6.5EG 6.52022-10-06
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocati…
- CVE-2022-40246HIGHCVSS 7.2EG 7.22022-09-20
A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mode) and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disc…
- CVE-2022-40250HIGHCVSS 8.8EG 8.82022-09-20
An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running …
- CVE-2022-40262HIGHCVSS 8.2EG 8.22022-09-20
A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Vi…
- CVE-2022-40363MEDIUMCVSS 5.5EG 5.52022-09-29
A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.
- CVE-2022-40510CRITICALCVSS 9.8EG 9.82023-08-08
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
- CVE-2022-40514CRITICALCVSS 9.8EG 9.82023-02-12
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
- CVE-2022-40516HIGHCVSS 8.4EG 7.82023-01-09
Memory corruption in Core due to stack-based buffer overflow.
- CVE-2022-40517HIGHCVSS 8.4EG 7.82023-01-09
Memory corruption in core due to stack-based buffer overflow
- CVE-2022-40520HIGHCVSS 8.4EG 7.82023-01-09
Memory corruption due to stack-based buffer overflow in Core
- CVE-2022-40641HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40644HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40648HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40650HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40651HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40652HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40653HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40654HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- CVE-2022-40655HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40657HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40658HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40659HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40660HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40661HIGHCVSS 7.8EG 7.82022-09-15
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2022-40717HIGHCVSS 8.8EG 8.82023-01-26
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the anweb service, whic…
- CVE-2022-40718HIGHCVSS 8.8EG 8.82023-01-26
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the anweb service, whic…
- CVE-2022-40784HIGHCVSS 8.8EG 8.82022-09-26
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.
- CVE-2022-40851CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
- CVE-2022-40853CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
- CVE-2022-40854CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
- CVE-2022-40855CRITICALCVSS 9.8EG 9.82022-09-23
Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via…
- CVE-2022-40860CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList
- CVE-2022-40861HIGHCVSS 7.2EG 7.22022-09-23
Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/
- CVE-2022-40862CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
- CVE-2022-40864CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet
- CVE-2022-40865CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/
- CVE-2022-40866CRITICALCVSS 9.8EG 9.82022-09-23
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/
- CVE-2022-40867CRITICALCVSS 9.8EG 9.82022-09-23
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/
- CVE-2022-40868CRITICALCVSS 9.8EG 9.82022-09-23
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/
- CVE-2022-40869CRITICALCVSS 9.8EG 9.82022-09-23
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").
- CVE-2022-40874HIGHCVSS 7.5EG 7.52022-10-27
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.
- CVE-2022-40875HIGHCVSS 7.5EG 7.52022-10-27
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
- CVE-2022-40876CRITICALCVSS 9.8EG 9.82022-10-27
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
- CVE-2022-40918CRITICALCVSS 9.8EG 9.82022-12-06
Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to…
- CVE-2022-40942CRITICALCVSS 9.8EG 9.82022-09-28
Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.
- CVE-2022-40961MEDIUMCVSS 6.5EG 6.52022-12-22
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vuln…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →