CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 165 of 279
- CVE-2022-45703HIGHCVSS 7.8EG 7.82023-08-22
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.
- CVE-2022-45766CRITICALCVSS 9.1EG 9.12023-02-10
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic …
- CVE-2022-45781HIGHCVSS 8.8EG 8.82023-11-14
Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.
- CVE-2022-45957HIGHCVSS 7.5EG 7.52022-12-12
ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.
- CVE-2022-45979HIGHCVSS 7.5EG 7.52022-12-12
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .
- CVE-2022-4608HIGHCVSS 7.5EG 7.52023-07-26
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session res…
- CVE-2022-46109HIGHCVSS 7.5EG 7.52022-12-16
Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.
- CVE-2022-46289CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a m…
- CVE-2022-46290CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a m…
- CVE-2022-46291CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code …
- CVE-2022-46292CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code …
- CVE-2022-46293CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code …
- CVE-2022-46294CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code …
- CVE-2022-46295CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code …
- CVE-2022-46319CRITICALCVSS 9.8EG 9.82022-12-20
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
- CVE-2022-46322HIGHCVSS 7.5EG 7.52022-12-20
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- CVE-2022-46323CRITICALCVSS 9.8EG 9.82022-12-20
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- CVE-2022-46324CRITICALCVSS 9.8EG 9.82022-12-20
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- CVE-2022-46325CRITICALCVSS 9.8EG 9.82022-12-20
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- CVE-2022-46326CRITICALCVSS 9.8EG 9.82022-12-20
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- CVE-2022-4634HIGHCVSS 7.8EG 7.82023-02-03
All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.
- CVE-2022-46340HIGHCVSS 8.8EG 8.82022-12-14
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XT…
- CVE-2022-46341HIGHCVSS 8.8EG 8.82022-12-14
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevat…
- CVE-2022-46345HIGHCVSS 7.8EG 7.82022-12-13
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All v…
- CVE-2022-46346HIGHCVSS 7.8EG 7.82022-12-13
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All v…
- CVE-2022-46347HIGHCVSS 7.8EG 7.82022-12-13
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All v…
- CVE-2022-46348HIGHCVSS 7.8EG 7.82022-12-13
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All v…
- CVE-2022-46393CRITICALCVSS 9.8EG 9.82022-12-15
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2…
- CVE-2022-46449HIGHCVSS 7.5EG 7.52023-01-10
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2022-46475CRITICALCVSS 9.8EG 9.82023-01-17
D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.
- CVE-2022-46560HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan2Settings module.
- CVE-2022-46561HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWanSettings module.
- CVE-2022-46562HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK parameter in the SetQuickVPNSettings module.
- CVE-2022-46563HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetDynamicDNSSettings module.
- CVE-2022-46566HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module.
- CVE-2022-46568HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.
- CVE-2022-46569HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key parameter in the SetWLanRadioSecurity module.
- CVE-2022-46570HIGHCVSS 7.2EG 7.22022-12-23
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan3Settings module.
- CVE-2022-46580CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.
- CVE-2022-46581CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.
- CVE-2022-46582CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.
- CVE-2022-46583CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.
- CVE-2022-46584CRITICALCVSS 9.8EG 7.52022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.
- CVE-2022-46585CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.
- CVE-2022-46586CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.
- CVE-2022-46588CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
- CVE-2022-46589CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.
- CVE-2022-46590CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.
- CVE-2022-46591CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.
- CVE-2022-46592CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →