CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 160 of 279
- CVE-2022-42423HIGHCVSS 7.8EG 7.82023-01-26
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic…
- CVE-2022-42475CRITICALCVSS 9.8EG 9.8⚠ KEV2023-01-02
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlie…
- CVE-2022-42498CRITICALCVSS 9.8EG 9.82023-03-24
In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Pro…
- CVE-2022-42499CRITICALCVSS 9.8EG 9.82023-03-24
In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed …
- CVE-2022-42501MEDIUMCVSS 6.7EG 6.72022-12-16
In HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2022-42502MEDIUMCVSS 6.7EG 6.72022-12-16
In FacilityLock::Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…
- CVE-2022-42503MEDIUMCVSS 6.7EG 6.72022-12-16
In ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges nee…
- CVE-2022-42504MEDIUMCVSS 6.7EG 6.72022-12-16
In CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction i…
- CVE-2022-42505MEDIUMCVSS 6.7EG 6.72022-12-16
In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges ne…
- CVE-2022-42506MEDIUMCVSS 6.7EG 6.72022-12-16
In SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…
- CVE-2022-42507MEDIUMCVSS 6.7EG 6.72022-12-16
In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User…
- CVE-2022-42508MEDIUMCVSS 6.7EG 6.72022-12-16
In ProtocolCallBuilder::BuildSendUssd of protocolcallbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interac…
- CVE-2022-42509MEDIUMCVSS 6.7EG 6.72022-12-16
In CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed …
- CVE-2022-42511MEDIUMCVSS 6.7EG 6.72022-12-16
In EmbmsSessionData::encode of embmsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed f…
- CVE-2022-42513MEDIUMCVSS 6.7EG 6.72022-12-16
In ProtocolEmbmsBuilder::BuildSetSession of protocolembmsbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User int…
- CVE-2022-42518MEDIUMCVSS 6.7EG 6.72022-12-16
In BroadcastSmsConfigsRequestData::encode of smsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is …
- CVE-2022-42519MEDIUMCVSS 6.7EG 6.72022-12-16
In CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…
- CVE-2022-42521MEDIUMCVSS 6.7EG 6.72022-12-16
In encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2022-42523MEDIUMCVSS 6.7EG 6.72022-12-16
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…
- CVE-2022-42525MEDIUMCVSS 6.7EG 6.72022-12-16
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…
- CVE-2022-42526MEDIUMCVSS 6.7EG 6.72022-12-16
In ConvertUtf8ToUcs2 of radio_hal_utils.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo…
- CVE-2022-42542MEDIUMCVSS 6.7EG 6.72022-12-16
In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee…
- CVE-2022-42755MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42772MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42783MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-42795HIGHCVSS 8.8EG 8.82022-11-01
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
- CVE-2022-42808CRITICALCVSS 9.8EG 9.82022-11-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
- CVE-2022-42820HIGHCVSS 7.8EG 7.82022-11-01
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may cause unexpected app termination or arbitrary code execution.
- CVE-2022-42827HIGHCVSS 7.8EG 9.0⚠ KEV2022-11-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aw…
- CVE-2022-42830MEDIUMCVSS 6.7EG 6.72022-11-01
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42840HIGHCVSS 7.8EG 7.82022-12-15
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary …
- CVE-2022-42842CRITICALCVSS 9.8EG 9.82022-12-15
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code…
- CVE-2022-42845HIGHCVSS 7.2EG 7.22022-12-15
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to exe…
- CVE-2022-42847HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42850HIGHCVSS 7.8EG 7.82022-12-15
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42858HIGHCVSS 7.8EG 7.82023-04-10
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges
- CVE-2022-42863HIGHCVSS 8.8EG 8.82022-12-15
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitr…
- CVE-2022-42901HIGHCVSS 7.8EG 7.82022-10-13
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMT files. Exploiting these issues could lead to information disclosure and code execution. The fixed …
- CVE-2022-4291HIGHCVSS 7.7EG 10.02022-12-08
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue wa…
- CVE-2022-42920CRITICALCVSS 9.8EG 9.82022-11-07
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in …
- CVE-2022-42932HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of th…
- CVE-2022-42933HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-42934HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-42935HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-42936HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-42937HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to co…
- CVE-2022-42938HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the …
- CVE-2022-42939HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the …
- CVE-2022-42940HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the …
- CVE-2022-42941HIGHCVSS 7.8EG 7.82022-10-21
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →