CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 158 of 279
- CVE-2022-41301HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to cod…
- CVE-2022-41304HIGHCVSS 7.8EG 7.82022-10-14
An Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK 2020 version and prior may lead to code execution through maliciously crafted FBX files or information disclosure.
- CVE-2022-41305HIGHCVSS 7.8EG 7.82022-10-14
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-41306HIGHCVSS 7.8EG 7.82022-10-14
A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code exec…
- CVE-2022-41307HIGHCVSS 7.8EG 7.82022-10-14
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to cod…
- CVE-2022-41308HIGHCVSS 7.8EG 7.82022-10-14
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to cod…
- CVE-2022-41309HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-41310HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-4135CRITICALCVSS 9.6EG 9.6⚠ KEV2022-11-25
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-4141HIGHCVSS 7.8EG 7.82022-11-25
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
- CVE-2022-41415CRITICALCVSS 9.8EG 9.82022-10-19
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.
- CVE-2022-41420MEDIUMCVSS 5.5EG 5.52022-10-03
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
- CVE-2022-41428HIGHCVSS 8.8EG 8.82022-10-03
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
- CVE-2022-41429HIGHCVSS 8.8EG 8.82022-10-03
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.
- CVE-2022-41430HIGHCVSS 8.8EG 8.82022-10-03
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
- CVE-2022-41517HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
- CVE-2022-41520HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
- CVE-2022-41521HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
- CVE-2022-41522CRITICALCVSS 9.8EG 9.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
- CVE-2022-41523HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
- CVE-2022-41524HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
- CVE-2022-41525CRITICALCVSS 9.8EG 9.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
- CVE-2022-41526HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
- CVE-2022-41527HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
- CVE-2022-41528HIGHCVSS 8.8EG 8.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
- CVE-2022-41578CRITICALCVSS 9.8EG 7.82022-10-14
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.
- CVE-2022-41592LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41593LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41594LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41595LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41597LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41598LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41600LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41601LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41602LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41603LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41639CRITICALCVSS 9.8EG 9.82022-12-22
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can resul…
- CVE-2022-41660HIGHCVSS 7.8EG 7.82022-11-08
A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions <…
- CVE-2022-41664HIGHCVSS 7.8EG 7.82022-11-08
A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions <…
- CVE-2022-41674HIGHCVSS 8.1EG 8.12022-10-14
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
- CVE-2022-41686MEDIUMCVSS 5.1EG 4.42022-10-14
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run …
- CVE-2022-41741HIGHCVSS 7.0EG 7.82022-10-19
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a…
- CVE-2022-41742HIGHCVSS 7.1EG 7.12022-10-19
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a…
- CVE-2022-41743HIGHCVSS 7.0EG 7.02022-10-19
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafte…
- CVE-2022-4176HIGHCVSS 8.8EG 8.82022-11-30
Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI inter…
- CVE-2022-41793CRITICALCVSS 9.8EG 9.82023-07-21
An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious …
- CVE-2022-41794CRITICALCVSS 9.8EG 9.82022-12-22
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger th…
- CVE-2022-41802MEDIUMCVSS 4.0EG 3.32022-12-08
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- CVE-2022-41837CRITICALCVSS 9.8EG 9.82022-12-22
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can pro…
- CVE-2022-41838CRITICALCVSS 9.8EG 9.82022-12-22
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger t…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →