CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,914 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 167 of 279
- CVE-2022-47380HIGHCVSS 8.8EG 8.82023-05-15
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting,…
- CVE-2022-47381HIGHCVSS 8.8EG 8.82023-05-15
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, o…
- CVE-2022-47382HIGHCVSS 8.8EG 8.82023-05-15
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service con…
- CVE-2022-47383HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47384HIGHCVSS 8.8EG 8.82023-05-15
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service con…
- CVE-2022-47385HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47386HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47387HIGHCVSS 8.8EG 8.82023-05-15
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service con…
- CVE-2022-47388HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47389HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47390HIGHCVSS 8.8EG 8.82023-05-15
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service co…
- CVE-2022-47452MEDIUMCVSS 5.5EG 5.52023-02-12
In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-47457MEDIUMCVSS 5.5EG 5.52023-03-10
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-47459MEDIUMCVSS 5.5EG 5.52023-03-10
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- CVE-2022-47469MEDIUMCVSS 4.4EG 4.42023-05-09
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.
- CVE-2022-47470MEDIUMCVSS 4.4EG 4.42023-05-09
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.
- CVE-2022-47485MEDIUMCVSS 4.4EG 4.42023-05-09
In modem control device, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-47486MEDIUMCVSS 4.4EG 4.42023-05-09
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-47517HIGHCVSS 7.5EG 7.52022-12-18
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that causes a url_canonize2 heap-based buffer over-read bec…
- CVE-2022-47518HIGHCVSS 7.8EG 7.82022-12-18
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when cop…
- CVE-2022-47519HIGHCVSS 7.8EG 7.82022-12-18
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when …
- CVE-2022-47521HIGHCVSS 7.8EG 7.82022-12-18
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow…
- CVE-2022-47655HIGHCVSS 7.8EG 7.82023-01-05
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>
- CVE-2022-47659HIGHCVSS 7.8EG 7.82023-01-05
GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data
- CVE-2022-47661HIGHCVSS 7.8EG 7.82023-01-05
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes
- CVE-2022-47665HIGHCVSS 7.8EG 7.82023-03-03
Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)
- CVE-2022-47908HIGHCVSS 7.8EG 7.82023-01-03
Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
- CVE-2022-47935HIGHCVSS 7.8EG 7.82023-01-10
A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains a memory corruption vulnerability while parsing specially crafte…
- CVE-2022-47942HIGHCVSS 8.8EG 8.82022-12-23
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.
- CVE-2022-47967HIGHCVSS 7.8EG 7.82023-01-10
A vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability that could be triggered while parsing files in different file formats such as PAR, ASM, DFT. This coul…
- CVE-2022-47977HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0). The affected application contains a memory corruption vulnerability while parsing specially crafted JT files. This could al…
- CVE-2022-48078CRITICALCVSS 9.8EG 9.82023-02-06
pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.
- CVE-2022-48130CRITICALCVSS 9.8EG 9.82023-02-02
Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.
- CVE-2022-48174CRITICALCVSS 9.8EG 9.82023-08-22
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
- CVE-2022-48176HIGHCVSS 7.8EG 7.82023-01-31
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.
- CVE-2022-48181MEDIUMCVSS 6.7EG 6.72023-06-05
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
- CVE-2022-48188MEDIUMCVSS 6.7EG 6.72023-06-05
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
- CVE-2022-48232MEDIUMCVSS 5.5EG 5.52023-05-09
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- CVE-2022-48233MEDIUMCVSS 5.5EG 5.52023-05-09
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- CVE-2022-48234MEDIUMCVSS 5.5EG 5.52023-05-09
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- CVE-2022-48235MEDIUMCVSS 4.4EG 4.42023-05-09
In MP3 encoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-48237MEDIUMCVSS 4.4EG 4.42023-05-09
In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-48238MEDIUMCVSS 4.4EG 4.42023-05-09
In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-48239MEDIUMCVSS 4.4EG 4.42023-05-09
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-48240MEDIUMCVSS 4.4EG 4.42023-05-09
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
- CVE-2022-48281MEDIUMCVSS 5.5EG 8.82023-01-23
processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
- CVE-2022-48312CRITICALCVSS 9.1EG 9.12023-04-16
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
- CVE-2022-48322CRITICALCVSS 9.8EG 9.82023-02-13
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.9…
- CVE-2022-48330HIGHCVSS 8.0EG 8.02023-06-16
A Huawei sound box product has an out-of-bounds write vulnerability. Attackers can exploit this vulnerability to cause buffer overflow. Affected product versions include:FLMG-10 versions FLMG-10 10.0.1.0(H100SP22C00).
- CVE-2022-48354MEDIUMCVSS 6.5EG 6.52023-03-27
The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →