CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,912 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 163 of 279
- CVE-2022-44198CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.
- CVE-2022-44199CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
- CVE-2022-44200CRITICALCVSS 9.8EG 9.82022-11-22
Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.
- CVE-2022-44202CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
- CVE-2022-44253HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
- CVE-2022-44254HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
- CVE-2022-44255CRITICALCVSS 9.8EG 9.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
- CVE-2022-44256HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
- CVE-2022-44257HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
- CVE-2022-44258HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
- CVE-2022-44259HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
- CVE-2022-44260HIGHCVSS 8.8EG 8.82022-11-23
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
- CVE-2022-44312MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator.
- CVE-2022-44313MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall.
- CVE-2022-44314MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExpressionParseFunctionCall.
- CVE-2022-44315MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c when called from ExpressionParseFunctionCall.
- CVE-2022-44316MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when called from LexScanGetToken.
- CVE-2022-44317MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall.
- CVE-2022-44318MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall.
- CVE-2022-44319MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall.
- CVE-2022-44320MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c when called from ExpressionParseFunctionCall.
- CVE-2022-44321MEDIUMCVSS 5.5EG 5.52022-11-08
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from LexScanGetToken.
- CVE-2022-44362CRITICALCVSS 9.8EG 9.82022-12-02
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
- CVE-2022-44363CRITICALCVSS 9.8EG 9.82022-12-02
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.
- CVE-2022-44365CRITICALCVSS 9.8EG 9.82022-12-02
Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.
- CVE-2022-44366CRITICALCVSS 9.8EG 9.82022-12-02
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.
- CVE-2022-44367CRITICALCVSS 9.8EG 9.82022-12-02
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.
- CVE-2022-44370HIGHCVSS 7.8EG 7.82023-03-29
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
- CVE-2022-44373HIGHCVSS 8.8EG 8.82022-12-07
A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution.
- CVE-2022-44427MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44428MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44429MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44430MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44431MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44448MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-44512HIGHCVSS 7.8EG 7.82024-12-19
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the curren…
- CVE-2022-44513HIGHCVSS 7.8EG 7.82024-12-19
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the curren…
- CVE-2022-44649HIGHCVSS 7.8EG 7.82022-12-12
An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker…
- CVE-2022-44650HIGHCVSS 7.8EG 7.82022-12-12
A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker mus…
- CVE-2022-44750CRITICALCVSS 9.8EG 7.82022-12-19
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro…
- CVE-2022-44751CRITICALCVSS 9.8EG 7.82022-12-19
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro …
- CVE-2022-44752CRITICALCVSS 9.8EG 7.82022-12-19
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect …
- CVE-2022-44753CRITICALCVSS 9.8EG 7.82022-12-19
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect f…
- CVE-2022-44754CRITICALCVSS 9.8EG 7.82022-12-19
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro…
- CVE-2022-44755CRITICALCVSS 9.8EG 7.82022-12-19
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro …
- CVE-2022-44789HIGHCVSS 8.8EG 8.82022-11-23
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
- CVE-2022-44804CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.
- CVE-2022-44806CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.
- CVE-2022-44807CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.
- CVE-2022-44840HIGHCVSS 7.8EG 7.82023-08-22
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →