CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,916 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 175 of 279
- CVE-2023-21663MEDIUMCVSS 6.7EG 6.72023-09-05
Memory Corruption while accessing metadata in Display.
- CVE-2023-21664HIGHCVSS 7.8EG 7.82023-09-05
Memory Corruption in Core Platform while printing the response buffer in log.
- CVE-2023-2194MEDIUMCVSS 6.7EG 6.72023-04-20
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond …
- CVE-2023-22226HIGHCVSS 7.8EG 7.82023-02-17
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue re…
- CVE-2023-22227HIGHCVSS 7.8EG 7.82023-02-17
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …
- CVE-2023-22229HIGHCVSS 7.8EG 7.82023-02-17
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …
- CVE-2023-22230HIGHCVSS 7.8EG 7.82023-02-17
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …
- CVE-2023-22234HIGHCVSS 7.8EG 7.82023-02-17
Adobe Premiere Rush version 2.6 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…
- CVE-2023-22236HIGHCVSS 7.8EG 7.82023-02-17
Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue re…
- CVE-2023-22237HIGHCVSS 7.8EG 7.82023-02-17
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2023-22238HIGHCVSS 7.8EG 7.82023-02-17
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2023-22240HIGHCVSS 7.8EG 7.82023-01-27
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2023-22241HIGHCVSS 7.8EG 7.82023-01-27
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2023-22242HIGHCVSS 7.8EG 7.82023-01-27
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
- CVE-2023-22243HIGHCVSS 7.8EG 7.82023-02-17
Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…
- CVE-2023-22327MEDIUMCVSS 6.0EG 6.02023-11-14
Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-22345HIGHCVSS 7.8EG 7.82023-02-13
Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a sp…
- CVE-2023-22351MEDIUMCVSS 6.1EG 6.12024-09-16
Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-22363MEDIUMCVSS 6.5EG 6.52023-07-25
A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)
- CVE-2023-22383MEDIUMCVSS 6.7EG 6.72023-12-05
Memory Corruption in camera while installing a fd for a particular DMA buffer.
- CVE-2023-22384MEDIUMCVSS 6.7EG 6.72023-10-03
Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).
- CVE-2023-22385HIGHCVSS 8.2EG 8.22023-10-03
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- CVE-2023-22386HIGHCVSS 7.8EG 7.82023-07-04
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
- CVE-2023-22388CRITICALCVSS 9.8EG 9.82023-11-07
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- CVE-2023-22404MEDIUMCVSS 6.5EG 6.52023-01-13
An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS). iked w…
- CVE-2023-2241MEDIUMCVSS 5.3EG 5.32023-04-22
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to b…
- CVE-2023-22411HIGHCVSS 7.5EG 7.52023-01-13
An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On SRX Series devices using Unified Policies with IPv6,…
- CVE-2023-22415HIGHCVSS 7.5EG 7.52023-01-13
An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all MX Series and SRX Series platform, when H.323 ALG is enabled and …
- CVE-2023-22435HIGHCVSS 7.5EG 7.52023-07-13
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
- CVE-2023-22442HIGHCVSS 7.9EG 7.92023-05-10
Out of bounds write in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
- CVE-2023-22612HIGHCVSS 8.8EG 8.82023-04-11
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.
- CVE-2023-22613HIGHCVSS 8.8EG 8.82023-04-11
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, re…
- CVE-2023-22614HIGHCVSS 8.8EG 8.82023-04-11
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BI…
- CVE-2023-22615HIGHCVSS 8.4EG 8.42023-04-11
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHI…
- CVE-2023-2262CRITICALCVSS 9.8EG 9.82023-09-20
A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vuln…
- CVE-2023-22639MEDIUMCVSS 6.7EG 6.72023-06-13
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, …
- CVE-2023-22640HIGHCVSS 7.5EG 7.52023-05-03
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 th…
- CVE-2023-22666HIGHCVSS 8.4EG 8.42023-08-08
Memory Corruption in Audio while playing amrwbplus clips with modified content.
- CVE-2023-22669HIGHCVSS 7.8EG 7.82023-04-15
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerabilit…
- CVE-2023-22670HIGHCVSS 7.8EG 7.82023-04-15
A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the…
- CVE-2023-22741CRITICALCVSS 9.8EG 9.82023-01-19
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controlla…
- CVE-2023-22751CRITICALCVSS 9.8EG 9.82023-03-01
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Su…
- CVE-2023-22752CRITICALCVSS 9.8EG 9.82023-03-01
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Su…
- CVE-2023-22842HIGHCVSS 7.5EG 7.52023-02-01
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Man…
- CVE-2023-2290MEDIUMCVSS 6.4EG 6.42023-06-26
A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2023-23082MEDIUMCVSS 4.6EG 4.62023-02-03
A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.
- CVE-2023-23086CRITICALCVSS 9.8EG 9.82023-02-03
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
- CVE-2023-23088CRITICALCVSS 9.8EG 9.82023-02-03
Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
- CVE-2023-23306CRITICALCVSS 9.8EG 9.82023-05-23
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted…
- CVE-2023-23376HIGHCVSS 7.8EG 9.0⚠ KEV2023-02-14
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →