CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,916 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 170 of 279
- CVE-2023-0341HIGHCVSS 7.8EG 7.82023-02-01
A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this v…
- CVE-2023-0618HIGHCVSS 7.5EG 7.52023-02-01
A vulnerability was found in TRENDnet TEW-652BRP 3.04B01. It has been declared as critical. This vulnerability affects unknown code of the file cfg_op.ccp of the component Web Service. The manipulation leads to memory corruption. The attac…
- CVE-2023-0622HIGHCVSS 7.8EG 7.82023-03-09
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated …
- CVE-2023-0623HIGHCVSS 7.8EG 7.82023-03-09
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated …
- CVE-2023-0637MEDIUMCVSS 6.5EG 6.52023-02-02
A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is po…
- CVE-2023-0656HIGHCVSS 7.5EG 7.52023-03-02
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
- CVE-2023-0666MEDIUMCVSS 6.5EG 8.82023-06-07
Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process r…
- CVE-2023-0667MEDIUMCVSS 6.5EG 9.82023-06-07
Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the contex…
- CVE-2023-0668MEDIUMCVSS 6.5EG 6.52023-06-07
Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the p…
- CVE-2023-0701HIGHCVSS 8.8EG 8.82023-02-07
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security sever…
- CVE-2023-0760HIGHCVSS 7.8EG 7.82023-02-09
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
- CVE-2023-0770HIGHCVSS 7.8EG 7.82023-02-09
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.
- CVE-2023-0782HIGHCVSS 7.2EG 9.82023-02-11
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack …
- CVE-2023-0800MEDIUMCVSS 6.8EG 5.52023-02-13
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
- CVE-2023-0801MEDIUMCVSS 6.8EG 5.52023-02-13
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile lib…
- CVE-2023-0802MEDIUMCVSS 6.8EG 5.52023-02-13
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
- CVE-2023-0803MEDIUMCVSS 6.8EG 5.52023-02-13
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
- CVE-2023-0804MEDIUMCVSS 6.8EG 5.52023-02-13
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
- CVE-2023-0819HIGHCVSS 7.8EG 7.82023-02-13
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
- CVE-2023-0841MEDIUMCVSS 6.3EG 8.82023-02-15
A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3_dmx_process of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. Th…
- CVE-2023-0847MEDIUMCVSS 5.3EG 8.12023-03-01
The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write prior to implementation version 0.5.0. If the protocol has been compiled using default settings, this will only grant t…
- CVE-2023-0851CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arb…
- CVE-2023-0852CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to…
- CVE-2023-0853CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execu…
- CVE-2023-0854CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unrespons…
- CVE-2023-0855CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute ar…
- CVE-2023-0856CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitr…
- CVE-2023-0930HIGHCVSS 8.8EG 8.82023-02-22
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-0969LOWCVSS 3.5EG 3.52023-06-21
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.
- CVE-2023-0970HIGHCVSS 7.1EG 7.12023-06-21
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.
- CVE-2023-0972CRITICALCVSS 9.6EG 9.62023-06-21
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
- CVE-2023-0977MEDIUMCVSS 6.7EG 6.52023-04-03
A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable.
- CVE-2023-1017HIGHCVSS 7.8EG 7.82023-02-28
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability ca…
- CVE-2023-1073MEDIUMCVSS 6.6EG 6.62023-03-27
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- CVE-2023-1078HIGHCVSS 7.8EG 7.82023-03-27
A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type con…
- CVE-2023-1217MEDIUMCVSS 6.5EG 6.52023-03-07
Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HT…
- CVE-2023-1219HIGHCVSS 8.8EG 8.82023-03-07
Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-1220HIGHCVSS 8.8EG 8.82023-03-07
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-1222HIGHCVSS 8.8EG 8.82023-03-07
Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-1388MEDIUMCVSS 6.3EG 6.32023-06-07
A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming unavailable.
- CVE-2023-1529CRITICALCVSS 9.8EG 9.82023-03-21
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
- CVE-2023-1579HIGHCVSS 7.8EG 7.82023-04-03
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
- CVE-2023-1646MEDIUMCVSS 5.3EG 7.82023-03-26
A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulat…
- CVE-2023-1709HIGHCVSS 7.8EG 7.82023-06-07
Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.
- CVE-2023-1729MEDIUMCVSS 6.5EG 6.52023-05-15
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
- CVE-2023-1801MEDIUMCVSS 6.5EG 9.82023-04-07
The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.
- CVE-2023-1810HIGHCVSS 8.8EG 8.82023-04-04
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-1812HIGHCVSS 8.8EG 8.82023-04-04
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-1820HIGHCVSS 8.8EG 8.82023-04-04
Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium s…
- CVE-2023-1901MEDIUMCVSS 5.9EG 5.92023-07-10
The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash …
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →