CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,916 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 171 of 279
- CVE-2023-1906MEDIUMCVSS 5.5EG 5.52023-04-12
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allo…
- CVE-2023-1945MEDIUMCVSS 6.5EG 6.52023-06-02
Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.
- CVE-2023-1972MEDIUMCVSS 6.5EG 6.52023-05-17
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
- CVE-2023-20032CRITICALCVSS 9.8EG 9.82023-03-01
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allo…
- CVE-2023-20078CRITICALCVSS 9.8EG 9.82023-03-03
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about th…
- CVE-2023-20079CRITICALCVSS 9.8EG 7.52023-03-03
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about th…
- CVE-2023-20081MEDIUMCVSS 6.8EG 5.92023-03-23
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remot…
- CVE-2023-20109MEDIUMCVSS 6.6EG 9.0⚠ KEV2023-09-27
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key ser…
- CVE-2023-20213MEDIUMCVSS 4.3EG 4.32023-11-01
A vulnerability in the CDP processing feature of Cisco ISE could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of the CDP process on an affected device. This vulnerability is due to insufficient b…
- CVE-2023-20250MEDIUMCVSS 6.5EG 6.52023-09-06
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is…
- CVE-2023-20513LOWCVSS 3.3EG 3.32024-08-13
An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.
- CVE-2023-20520CRITICALCVSS 9.8EG 9.82023-05-09
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
- CVE-2023-20524HIGHCVSS 7.5EG 7.52023-05-09
An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.
- CVE-2023-20555HIGHCVSS 7.8EG 7.82023-08-08
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
- CVE-2023-20604MEDIUMCVSS 6.7EG 6.72023-02-06
In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0749406…
- CVE-2023-20614MEDIUMCVSS 6.7EG 6.72023-02-06
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762861…
- CVE-2023-20615MEDIUMCVSS 6.7EG 6.72023-02-06
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762957…
- CVE-2023-20626MEDIUMCVSS 6.7EG 6.72023-03-07
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS074…
- CVE-2023-20630MEDIUMCVSS 6.7EG 6.72023-03-07
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762850…
- CVE-2023-20632MEDIUMCVSS 6.7EG 6.72023-03-07
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762850…
- CVE-2023-20634MEDIUMCVSS 6.7EG 6.72023-03-07
In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2023-20652MEDIUMCVSS 6.7EG 6.72023-04-06
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-20653MEDIUMCVSS 6.7EG 6.72023-04-06
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-20654MEDIUMCVSS 6.7EG 6.72023-04-06
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-20656MEDIUMCVSS 6.7EG 6.72023-04-06
In geniezone, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07571494; …
- CVE-2023-20657MEDIUMCVSS 6.7EG 6.72023-04-06
In mtee, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS075714…
- CVE-2023-20658MEDIUMCVSS 6.7EG 6.72023-04-06
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0753739…
- CVE-2023-20659MEDIUMCVSS 6.7EG 6.72023-04-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS075884…
- CVE-2023-20666MEDIUMCVSS 6.7EG 6.72023-04-06
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2023-20670MEDIUMCVSS 6.7EG 6.72023-04-06
In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648…
- CVE-2023-20681MEDIUMCVSS 6.7EG 6.72023-04-06
In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076…
- CVE-2023-20694MEDIUMCVSS 6.7EG 6.72023-05-15
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20695MEDIUMCVSS 6.7EG 6.72023-05-15
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20696MEDIUMCVSS 6.7EG 6.72023-05-15
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20699MEDIUMCVSS 6.7EG 6.72023-05-15
In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076960…
- CVE-2023-20700MEDIUMCVSS 6.7EG 6.72023-05-15
In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643304; I…
- CVE-2023-20701MEDIUMCVSS 6.7EG 6.72023-05-15
In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643270; I…
- CVE-2023-20712MEDIUMCVSS 6.7EG 6.72023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS077969…
- CVE-2023-20715MEDIUMCVSS 6.7EG 6.72023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS077969…
- CVE-2023-20716MEDIUMCVSS 6.7EG 6.72023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS077968…
- CVE-2023-2072HIGHCVSS 8.8EG 8.82023-07-11
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker whic…
- CVE-2023-20720MEDIUMCVSS 6.7EG 6.72023-05-15
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS…
- CVE-2023-20721MEDIUMCVSS 6.7EG 6.72023-05-15
In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0716…
- CVE-2023-20725MEDIUMCVSS 6.7EG 6.72023-06-06
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20732MEDIUMCVSS 6.7EG 6.72023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573480…
- CVE-2023-20734MEDIUMCVSS 6.7EG 6.72023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0764514…
- CVE-2023-20735MEDIUMCVSS 6.7EG 6.72023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0764514…
- CVE-2023-20736MEDIUMCVSS 6.4EG 6.42023-06-06
In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Iss…
- CVE-2023-20738MEDIUMCVSS 6.7EG 6.72023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0764514…
- CVE-2023-20739MEDIUMCVSS 6.7EG 6.72023-06-06
In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559819; Issue ID…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →