CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,922 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 182 of 279
- CVE-2023-27910HIGHCVSS 7.8EG 7.82023-04-17
A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
- CVE-2023-27911HIGHCVSS 7.8EG 7.82023-04-17
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
- CVE-2023-27914HIGHCVSS 7.8EG 7.82023-04-14
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensi…
- CVE-2023-27915HIGHCVSS 7.8EG 7.82023-04-14
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution …
- CVE-2023-27933MEDIUMCVSS 6.7EG 6.72023-05-08
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app with root privileges may be able to execute arbitrary code wi…
- CVE-2023-27936HIGHCVSS 7.8EG 7.82023-05-08
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to cause unexpected system …
- CVE-2023-27953CRITICALCVSS 9.8EG 9.82023-05-08
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2023-27959HIGHCVSS 7.8EG 7.82023-05-08
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-27965HIGHCVSS 7.8EG 7.82023-05-08
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Studio Display Firmware Update 16.4. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-27970HIGHCVSS 7.8EG 7.82023-05-08
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-27973CRITICALCVSS 9.8EG 9.82023-04-28
Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.
- CVE-2023-2798HIGHCVSS 7.5EG 7.52023-05-25
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. Th…
- CVE-2023-27997CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-13
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version …
- CVE-2023-2804MEDIUMCVSS 6.5EG 6.52023-05-25
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data ty…
- CVE-2023-28064LOWCVSS 3.5EG 3.52023-06-23
Dell BIOS contains an Out-of-bounds Write vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
- CVE-2023-28116HIGHCVSS 8.1EG 8.12023-03-17
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system. The network stack …
- CVE-2023-28176HIGHCVSS 8.8EG 8.82023-06-02
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabili…
- CVE-2023-28177HIGHCVSS 8.8EG 8.82023-06-02
Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 1…
- CVE-2023-28206HIGHCVSS 8.6EG 9.0⚠ KEV2023-04-10
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be …
- CVE-2023-28252HIGHCVSS 7.8EG 9.0⚠ KEV2023-04-11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-28379CRITICALCVSS 9.0EG 9.02023-11-14
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger …
- CVE-2023-28391CRITICALCVSS 9.0EG 9.02023-11-14
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger …
- CVE-2023-28393MEDIUMCVSS 5.6EG 8.82023-09-25
A stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file…
- CVE-2023-28401MEDIUMCVSS 5.7EG 5.72023-11-14
Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28410HIGHCVSS 8.8EG 8.82023-05-10
Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local a…
- CVE-2023-28445CRITICALCVSS 9.9EG 9.92023-03-24
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is …
- CVE-2023-28478HIGHCVSS 8.8EG 8.82023-06-12
TP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.
- CVE-2023-28488MEDIUMCVSS 6.5EG 6.52023-04-12
client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
- CVE-2023-28502CRITICALCVSS 9.8EG 9.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as t…
- CVE-2023-28504CRITICALCVSS 9.8EG 9.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
- CVE-2023-28506HIGHCVSS 8.8EG 8.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function…
- CVE-2023-28508HIGHCVSS 8.8EG 8.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked…
- CVE-2023-28523HIGHCVSS 8.4EG 8.42023-12-09
IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.
- CVE-2023-28526MEDIUMCVSS 6.2EG 6.22023-12-09
IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.
- CVE-2023-28527MEDIUMCVSS 6.2EG 6.22023-12-09
IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.
- CVE-2023-28537HIGHCVSS 8.4EG 8.42023-08-08
Memory corruption while allocating memory in COmxApeDec module in Audio.
- CVE-2023-28538HIGHCVSS 8.4EG 8.42023-09-05
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- CVE-2023-2854MEDIUMCVSS 5.3EG 5.32023-05-26
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVE-2023-28545HIGHCVSS 8.2EG 8.22023-11-07
Memory corruption in TZ Secure OS while loading an app ELF.
- CVE-2023-28547HIGHCVSS 8.4EG 8.42024-04-01
Memory corruption in SPS Application while requesting for public key in sorter TA.
- CVE-2023-2855MEDIUMCVSS 5.3EG 5.32023-05-26
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVE-2023-28550HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
- CVE-2023-28551HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
- CVE-2023-28558HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
- CVE-2023-28559HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
- CVE-2023-2856MEDIUMCVSS 5.3EG 5.32023-05-26
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVE-2023-28560HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- CVE-2023-28561CRITICALCVSS 9.8EG 9.82023-08-08
Memory corruption in QESL while processing payload from external ESL device to firmware.
- CVE-2023-28562CRITICALCVSS 9.8EG 9.82023-09-05
Memory corruption while handling payloads from remote ESL.
- CVE-2023-28564HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →