CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 162 of 279
- CVE-2022-43253MEDIUMCVSS 6.5EG 6.52022-11-02
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
- CVE-2022-43259HIGHCVSS 7.5EG 7.52022-10-18
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
- CVE-2022-43260CRITICALCVSS 9.8EG 9.82022-10-18
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
- CVE-2022-43281HIGHCVSS 7.8EG 7.82022-10-28
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
- CVE-2022-43285HIGHCVSS 7.5EG 7.52022-10-28
Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.
- CVE-2022-43289HIGHCVSS 7.8EG 7.82022-12-19
Deark v.1.6.2 was discovered to contain a stack overflow via the do_prism_read_palette() function at /modules/atari-img.c.
- CVE-2022-43294CRITICALCVSS 9.8EG 9.82022-11-14
Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libesp32/rtsp/CRtspSession.cpp.
- CVE-2022-43295MEDIUMCVSS 5.5EG 5.52022-11-14
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
- CVE-2022-43357HIGHCVSS 7.5EG 7.52023-08-22
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driv…
- CVE-2022-43358HIGHCVSS 7.5EG 7.52023-08-22
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
- CVE-2022-43397HIGHCVSS 7.8EG 7.82022-11-08
A vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Simcenter Femap (All versions < V2023.1). The affected application c…
- CVE-2022-43448HIGHCVSS 7.8EG 7.82023-01-03
Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted image file.
- CVE-2022-43467CRITICALCVSS 9.8EG 9.82023-07-21
An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malic…
- CVE-2022-43509HIGHCVSS 7.8EG 7.82022-12-07
Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
- CVE-2022-43598HIGHCVSS 8.1EG 8.12022-12-22
Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. An attacker can pro…
- CVE-2022-43604CRITICALCVSS 10.0EG 9.82023-03-16
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, pot…
- CVE-2022-43605CRITICALCVSS 10.0EG 9.82023-03-16
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, pot…
- CVE-2022-43607HIGHCVSS 8.1EG 8.12023-07-21
An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provi…
- CVE-2022-43614HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-43617HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-43618HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicio…
- CVE-2022-43653HIGHCVSS 7.8EG 7.82024-05-07
Bentley View SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View. User interaction is required to exploit …
- CVE-2022-43662MEDIUMCVSS 4.0EG 7.82023-01-09
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- CVE-2022-43667HIGHCVSS 7.8EG 8.82022-12-07
Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
- CVE-2022-43750MEDIUMCVSS 6.7EG 7.82022-10-26
drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.
- CVE-2022-43764CRITICALCVSS 9.8EG 9.82023-02-08
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.
- CVE-2022-4378HIGHCVSS 7.8EG 7.82023-01-05
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- CVE-2022-43931CRITICALCVSS 10.0EG 10.02023-01-03
Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2022-43970HIGHCVSS 7.2EG 7.22023-01-09
A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with admin…
- CVE-2022-44010HIGHCVSS 7.5EG 7.52023-11-23
An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This d…
- CVE-2022-44011MEDIUMCVSS 6.5EG 6.52023-11-23
An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.…
- CVE-2022-44079MEDIUMCVSS 5.5EG 5.52022-10-31
pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.
- CVE-2022-44108CRITICALCVSS 9.8EG 9.82022-12-19
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.
- CVE-2022-44109CRITICALCVSS 9.8EG 9.82022-12-19
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int).
- CVE-2022-44156HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.
- CVE-2022-44158HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.
- CVE-2022-44163HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
- CVE-2022-44167HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.
- CVE-2022-44168HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..
- CVE-2022-44169HIGHCVSS 7.5EG 7.52022-11-21
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.
- CVE-2022-44184CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.
- CVE-2022-44186CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.
- CVE-2022-44187CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.
- CVE-2022-44188CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.
- CVE-2022-44190CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.
- CVE-2022-44191CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.
- CVE-2022-44193CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.
- CVE-2022-44194CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
- CVE-2022-44196CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.
- CVE-2022-44197CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →