CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 164 of 279
- CVE-2022-44874MEDIUMCVSS 5.5EG 5.52022-12-13
wasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component op_CallIndirect at /m3_exec.h.
- CVE-2022-44898HIGHCVSS 7.8EG 7.82022-12-14
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS)…
- CVE-2022-44910HIGHCVSS 7.8EG 7.82022-12-14
Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.
- CVE-2022-44931HIGHCVSS 7.5EG 7.52022-12-08
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
- CVE-2022-4498CRITICALCVSS 9.8EG 9.82023-01-11
In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashi…
- CVE-2022-45126MEDIUMCVSS 4.0EG 7.82023-01-09
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- CVE-2022-45188HIGHCVSS 7.8EG 7.82022-11-12
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
- CVE-2022-45202HIGHCVSS 7.8EG 7.82022-11-29
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.
- CVE-2022-45283HIGHCVSS 7.8EG 7.82022-12-06
GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.
- CVE-2022-45332HIGHCVSS 7.8EG 7.82022-11-30
LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.
- CVE-2022-45337HIGHCVSS 7.5EG 7.52022-11-30
Tenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- CVE-2022-45406CRITICALCVSS 9.8EG 9.82022-12-22
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This v…
- CVE-2022-45421HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been …
- CVE-2022-45460CRITICALCVSS 9.8EG 9.82023-03-28
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the …
- CVE-2022-45491HIGHCVSS 7.8EG 7.82023-02-03
Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- CVE-2022-45492HIGHCVSS 7.8EG 7.82023-02-03
Buffer overflow vulnerability in function json_parse_number in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- CVE-2022-45493HIGHCVSS 7.8EG 7.82023-02-03
Buffer overflow vulnerability in function json_parse_key in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- CVE-2022-45494HIGHCVSS 7.8EG 7.82023-01-31
Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- CVE-2022-45496HIGHCVSS 7.8EG 7.82023-02-03
Buffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- CVE-2022-45499HIGHCVSS 7.5EG 9.82022-12-08
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.
- CVE-2022-45501HIGHCVSS 7.5EG 7.52022-12-08
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.
- CVE-2022-45503HIGHCVSS 7.5EG 7.52022-12-08
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.
- CVE-2022-45505HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
- CVE-2022-45507HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
- CVE-2022-45508HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
- CVE-2022-45509HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.
- CVE-2022-45510HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.
- CVE-2022-45511HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
- CVE-2022-45512HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.
- CVE-2022-45513HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.
- CVE-2022-45514HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.
- CVE-2022-45515HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.
- CVE-2022-45516HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.
- CVE-2022-45517HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.
- CVE-2022-45518HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.
- CVE-2022-45519HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
- CVE-2022-45520HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
- CVE-2022-45521HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
- CVE-2022-45522HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
- CVE-2022-45523HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
- CVE-2022-45524HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
- CVE-2022-45525HIGHCVSS 7.5EG 7.52022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.
- CVE-2022-45586MEDIUMCVSS 5.5EG 5.52023-02-15
Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- CVE-2022-45587MEDIUMCVSS 5.5EG 5.52023-02-15
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- CVE-2022-45640HIGHCVSS 7.5EG 7.52022-12-01
Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).
- CVE-2022-45685HIGHCVSS 7.5EG 7.52022-12-13
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
- CVE-2022-45688HIGHCVSS 7.5EG 7.52022-12-13
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
- CVE-2022-45689HIGHCVSS 7.5EG 7.52022-12-13
hutool-json v5.8.10 was discovered to contain an out of memory error.
- CVE-2022-45690HIGHCVSS 7.5EG 7.52022-12-13
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
- CVE-2022-45693HIGHCVSS 7.5EG 7.52022-12-13
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →