CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,921 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 177 of 279
- CVE-2023-24164CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
- CVE-2023-24165CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
- CVE-2023-24166CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
- CVE-2023-24167CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
- CVE-2023-24169CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
- CVE-2023-24170CRITICALCVSS 9.8EG 9.82023-01-26
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
- CVE-2023-24212CRITICALCVSS 9.8EG 9.82023-02-23
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
- CVE-2023-24295HIGHCVSS 7.8EG 7.82023-03-23
A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.
- CVE-2023-24343HIGHCVSS 8.8EG 8.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule.
- CVE-2023-24344HIGHCVSS 8.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.
- CVE-2023-24345HIGHCVSS 8.8EG 8.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus.
- CVE-2023-24346HIGHCVSS 8.8EG 8.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3.
- CVE-2023-24347HIGHCVSS 8.8EG 8.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus.
- CVE-2023-24348CRITICALCVSS 9.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.
- CVE-2023-24349CRITICALCVSS 9.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.
- CVE-2023-24350CRITICALCVSS 9.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.
- CVE-2023-24351CRITICALCVSS 9.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.
- CVE-2023-24352CRITICALCVSS 9.8EG 9.82023-02-10
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.
- CVE-2023-24474HIGHCVSS 7.5EG 7.52023-07-13
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
- CVE-2023-24480CRITICALCVSS 9.8EG 9.82023-07-13
Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-24560HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains an out of bounds write past the end of an allocated buffer while pars…
- CVE-2023-24566LOWCVSS 3.3EG 7.82023-02-14
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to stack-based buffer while pa…
- CVE-2023-2457HIGHCVSS 8.8EG 8.82023-05-12
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
- CVE-2023-24585HIGHCVSS 7.7EG 7.72023-11-14
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vuln…
- CVE-2023-24613MEDIUMCVSS 4.9EG 4.92023-02-03
The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after accessing the system with administrator privileges. A successful…
- CVE-2023-24797CRITICALCVSS 9.8EG 9.82023-04-07
D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- CVE-2023-24798CRITICALCVSS 9.8EG 9.82023-04-07
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- CVE-2023-24799CRITICALCVSS 9.8EG 9.82023-04-07
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- CVE-2023-24800CRITICALCVSS 9.8EG 9.82023-04-07
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- CVE-2023-24817HIGHCVSS 7.5EG 7.52023-05-30
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device resulting in an integer un…
- CVE-2023-24819CRITICALCVSS 9.8EG 9.82023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of…
- CVE-2023-24820HIGHCVSS 7.5EG 7.52023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of bounds write beyond …
- CVE-2023-24821HIGHCVSS 7.5EG 7.52023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a large o…
- CVE-2023-24823CRITICALCVSS 9.8EG 9.82023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type co…
- CVE-2023-24851HIGHCVSS 7.8EG 7.82023-07-04
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
- CVE-2023-24852HIGHCVSS 8.4EG 8.42023-11-07
Memory Corruption in Core due to secure memory access by user while loading modem image.
- CVE-2023-24853HIGHCVSS 8.4EG 8.42023-10-03
Memory Corruption in HLOS while registering for key provisioning notify.
- CVE-2023-24854HIGHCVSS 7.8EG 7.82023-07-04
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
- CVE-2023-24855CRITICALCVSS 9.8EG 9.82023-10-03
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- CVE-2023-24958HIGHCVSS 8.8EG 8.82023-05-04
A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM …
- CVE-2023-24979HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24980HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24981HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24982HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24983HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24984HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24985HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24986HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24987HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
- CVE-2023-24988HIGHCVSS 7.8EG 7.82023-02-14
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This c…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →