CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 166 of 279
- CVE-2022-46593CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function.
- CVE-2022-46594CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.
- CVE-2022-46596CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.
- CVE-2022-46597CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
- CVE-2022-46598CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.
- CVE-2022-46599CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.
- CVE-2022-46600CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function.
- CVE-2022-46601CRITICALCVSS 9.8EG 9.82022-12-30
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.
- CVE-2022-46690HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-46691HIGHCVSS 8.8EG 8.82022-12-15
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted …
- CVE-2022-46693HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead…
- CVE-2022-46694HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel c…
- CVE-2022-46696HIGHCVSS 8.8EG 8.82022-12-15
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitr…
- CVE-2022-46697HIGHCVSS 7.8EG 7.82022-12-15
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-46699HIGHCVSS 8.8EG 8.82022-12-15
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitr…
- CVE-2022-46700HIGHCVSS 8.8EG 8.82022-12-15
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted …
- CVE-2022-46709CRITICALCVSS 9.8EG 9.82023-04-10
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges
- CVE-2022-46721HIGHCVSS 7.8EG 7.82024-01-10
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-46723CRITICALCVSS 9.8EG 9.82023-02-27
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.
- CVE-2022-46878HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…
- CVE-2022-46879HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107. Some of these bugs showed evidence of memory corruption and we presum…
- CVE-2022-46881HIGHCVSS 8.8EG 8.82022-12-22
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. T…
- CVE-2022-46883HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough e…
- CVE-2022-46885HIGHCVSS 8.8EG 8.82022-12-22
Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c…
- CVE-2022-47065HIGHCVSS 8.8EG 8.82023-01-23
TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule. This vulnerability allows attackers to execute arbitrary code via a …
- CVE-2022-47069HIGHCVSS 7.8EG 7.82023-08-22
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buffer overflow; at mos…
- CVE-2022-47086MEDIUMCVSS 5.5EG 5.52023-01-05
GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c
- CVE-2022-47115CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.
- CVE-2022-47116HIGHCVSS 7.5EG 7.52022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.
- CVE-2022-47117CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.
- CVE-2022-47118CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.
- CVE-2022-47119CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.
- CVE-2022-47120CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
- CVE-2022-47121CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.
- CVE-2022-47122CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet.
- CVE-2022-47123CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.
- CVE-2022-47124CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.
- CVE-2022-47125CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.
- CVE-2022-47126CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.
- CVE-2022-47127CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet.
- CVE-2022-47128CRITICALCVSS 9.8EG 9.82022-12-30
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.
- CVE-2022-47317HIGHCVSS 7.8EG 7.82023-01-03
Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
- CVE-2022-47337MEDIUMCVSS 5.5EG 5.52023-04-11
In media service, there is a missing permission check. This could lead to local denial of service in media service.
- CVE-2022-47340MEDIUMCVSS 5.5EG 5.52023-05-09
In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-47364MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-47365MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-47366MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-47368MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-47369MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-47379HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code …
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →