CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,916 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 173 of 279
- CVE-2023-20841MEDIUMCVSS 6.5EG 6.52023-09-04
In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS…
- CVE-2023-20842MEDIUMCVSS 6.5EG 6.52023-09-04
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID…
- CVE-2023-20850MEDIUMCVSS 6.5EG 6.52023-09-04
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID:…
- CVE-2023-20869HIGHCVSS 8.2EG 8.22023-04-25
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
- CVE-2023-20872HIGHCVSS 8.8EG 8.82023-04-25
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
- CVE-2023-20892HIGHCVSS 8.1EG 8.12023-06-22
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerabil…
- CVE-2023-20894HIGHCVSS 8.1EG 8.22023-06-22
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted…
- CVE-2023-20895HIGHCVSS 8.1EG 8.12023-06-22
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass auth…
- CVE-2023-20905HIGHCVSS 7.8EG 7.82023-01-26
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not …
- CVE-2023-20931HIGHCVSS 7.8EG 7.82023-03-24
In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2023-20936HIGHCVSS 7.8EG 7.82023-03-24
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-20941MEDIUMCVSS 6.6EG 6.62023-04-19
In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2023-20945HIGHCVSS 7.8EG 7.82023-02-28
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2023-20949MEDIUMCVSS 5.5EG 5.52023-02-15
In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee…
- CVE-2023-20951CRITICALCVSS 9.8EG 9.82023-03-24
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2023-20952MEDIUMCVSS 5.5EG 5.52023-03-24
In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need…
- CVE-2023-20954CRITICALCVSS 9.8EG 9.82023-03-24
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2023-20956MEDIUMCVSS 4.4EG 4.42023-03-24
In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat…
- CVE-2023-20966HIGHCVSS 7.8EG 7.82023-03-24
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2023-20967HIGHCVSS 7.8EG 7.82023-04-19
In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2023-20985HIGHCVSS 7.8EG 7.82023-03-24
In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2023-20994MEDIUMCVSS 6.7EG 6.72023-03-24
In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not …
- CVE-2023-21022HIGHCVSS 7.8EG 7.82023-03-24
In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2023-21038MEDIUMCVSS 6.7EG 6.72023-03-24
In cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex…
- CVE-2023-21040HIGHCVSS 7.8EG 7.82023-03-24
In buildCommand of bluetooth_ccc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2023-21041HIGHCVSS 7.8EG 7.82023-03-24
In append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2023-21046MEDIUMCVSS 4.4EG 4.42023-03-24
In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for …
- CVE-2023-21050MEDIUMCVSS 6.7EG 6.72023-03-24
In load_png_image of ExynosHWCHelper.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo…
- CVE-2023-21051MEDIUMCVSS 6.7EG 6.72023-03-24
In dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is …
- CVE-2023-21052MEDIUMCVSS 6.7EG 6.72023-03-24
In setToExternal of ril_external_client.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo…
- CVE-2023-21054HIGHCVSS 7.2EG 7.22023-03-24
In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not neede…
- CVE-2023-21057CRITICALCVSS 9.8EG 9.82023-03-24
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not neede…
- CVE-2023-21058CRITICALCVSS 9.8EG 9.82023-03-24
In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed …
- CVE-2023-21066CRITICALCVSS 9.8EG 9.82023-06-28
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Pr…
- CVE-2023-21069MEDIUMCVSS 6.7EG 6.72023-03-24
In wl_update_hidden_ap_ie of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for …
- CVE-2023-21070MEDIUMCVSS 6.7EG 6.72023-03-24
In add_roam_cache_list of wl_roam.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi…
- CVE-2023-21071MEDIUMCVSS 6.7EG 6.72023-03-24
In dhd_prot_ioctcmplt_process of dhd_msgbuf.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not need…
- CVE-2023-21072MEDIUMCVSS 6.7EG 6.72023-03-24
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21073MEDIUMCVSS 6.7EG 6.72023-03-24
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21075MEDIUMCVSS 6.7EG 6.72023-03-24
In get_svc_hash of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pr…
- CVE-2023-21076MEDIUMCVSS 6.7EG 6.72023-03-24
In createTransmitFollowupRequest of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo…
- CVE-2023-21077MEDIUMCVSS 6.7EG 6.72023-03-24
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21078MEDIUMCVSS 6.7EG 6.72023-03-24
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21079MEDIUMCVSS 6.7EG 6.72023-03-24
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo…
- CVE-2023-21085HIGHCVSS 8.8EG 8.82023-04-19
In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interactio…
- CVE-2023-21100HIGHCVSS 7.8EG 7.82023-04-19
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2023-21151MEDIUMCVSS 6.7EG 6.72023-06-28
In the Google BMS kernel module, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21157MEDIUMCVSS 6.7EG 6.72023-06-28
In encode of wlandata.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro…
- CVE-2023-21159MEDIUMCVSS 6.7EG 6.72023-06-28
In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ…
- CVE-2023-21161MEDIUMCVSS 6.7EG 6.72023-06-28
In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →