CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,916 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 174 of 279
- CVE-2023-21222MEDIUMCVSS 6.7EG 6.72023-06-28
In load_dt_data of storage.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2023-21236MEDIUMCVSS 6.7EG 6.72023-06-28
In aoc_service_set_read_blocked of aoc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e…
- CVE-2023-2124HIGHCVSS 7.8EG 7.82023-05-15
An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privil…
- CVE-2023-21250CRITICALCVSS 9.8EG 9.82023-07-13
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2023-21255HIGHCVSS 7.8EG 7.82023-07-13
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2023-21273HIGHCVSS 8.8EG 8.82023-08-14
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is no…
- CVE-2023-21282HIGHCVSS 8.8EG 8.82023-08-14
In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploit…
- CVE-2023-21310MEDIUMCVSS 6.7EG 6.72023-10-30
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-2133HIGHCVSS 8.8EG 8.82023-04-19
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-2134HIGHCVSS 8.8EG 8.82023-04-19
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-21356HIGHCVSS 8.8EG 8.82023-10-30
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21360MEDIUMCVSS 6.7EG 6.72023-10-30
In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-2137HIGHCVSS 8.8EG 8.82023-04-19
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-21380MEDIUMCVSS 6.7EG 6.72023-10-30
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21385MEDIUMCVSS 5.5EG 5.52023-10-30
In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21406HIGHCVSS 7.1EG 7.12023-07-25
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of th…
- CVE-2023-21451MEDIUMCVSS 6.7EG 7.82023-02-09
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
- CVE-2023-21475HIGHCVSS 8.0EG 7.82025-09-03
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-21476HIGHCVSS 8.0EG 7.82025-09-03
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-21489HIGHCVSS 7.1EG 7.12023-05-04
Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.
- CVE-2023-21499HIGHCVSS 8.2EG 8.22023-05-04
Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-21506MEDIUMCVSS 6.7EG 6.72023-05-04
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
- CVE-2023-21508MEDIUMCVSS 6.7EG 6.72023-05-04
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
- CVE-2023-21509MEDIUMCVSS 6.7EG 6.72023-05-04
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
- CVE-2023-21517HIGHCVSS 8.8EG 8.82023-06-28
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code.
- CVE-2023-2157MEDIUMCVSS 5.5EG 5.52023-06-06
A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.
- CVE-2023-21575HIGHCVSS 7.8EG 7.82023-02-17
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2023-21576HIGHCVSS 7.8EG 7.82023-02-17
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2023-21582HIGHCVSS 7.8EG 7.82023-04-12
Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inter…
- CVE-2023-21589HIGHCVSS 7.8EG 7.82023-01-13
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2023-21590HIGHCVSS 7.8EG 7.82023-01-13
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2023-21595HIGHCVSS 7.8EG 7.82023-01-13
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2023-21597HIGHCVSS 7.8EG 7.82023-01-13
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2023-21606HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2023-21609HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2023-21619HIGHCVSS 7.8EG 7.82023-02-17
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2023-21622HIGHCVSS 7.8EG 7.82023-02-17
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2023-21628HIGHCVSS 8.4EG 8.42023-06-06
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
- CVE-2023-21632HIGHCVSS 8.4EG 8.42023-06-06
Memory corruption in Automotive GPU while querying a gsl memory node.
- CVE-2023-21633MEDIUMCVSS 6.7EG 6.72023-07-04
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
- CVE-2023-21634MEDIUMCVSS 6.7EG 6.72023-12-05
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
- CVE-2023-21635MEDIUMCVSS 6.7EG 6.72023-07-04
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
- CVE-2023-21637MEDIUMCVSS 6.7EG 6.72023-07-04
Memory corruption in Linux while calling system configuration APIs.
- CVE-2023-21639MEDIUMCVSS 6.7EG 6.72023-07-04
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
- CVE-2023-21640MEDIUMCVSS 6.7EG 6.72023-07-04
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
- CVE-2023-21643CRITICALCVSS 9.1EG 9.12023-08-08
Memory corruption due to untrusted pointer dereference in automotive during system call.
- CVE-2023-21648MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in RIL while trying to send apdu packet.
- CVE-2023-21649MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
- CVE-2023-21650MEDIUMCVSS 6.7EG 6.72023-08-08
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- CVE-2023-21654MEDIUMCVSS 6.7EG 6.72023-09-05
Memory corruption in Audio during playback session with audio effects enabled.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →