CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,922 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 183 of 279
- CVE-2023-28565HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- CVE-2023-28567HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while handling command through WMI interfaces.
- CVE-2023-2857MEDIUMCVSS 5.3EG 5.32023-05-26
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVE-2023-28570MEDIUMCVSS 6.7EG 7.82023-11-07
Memory corruption while processing audio effects.
- CVE-2023-28572MEDIUMCVSS 6.6EG 8.82023-11-07
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- CVE-2023-28573HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while parsing WMI command parameters.
- CVE-2023-28574CRITICALCVSS 9.0EG 9.02023-11-07
Memory corruption in core services when Diag handler receives a command to configure event listeners.
- CVE-2023-28578CRITICALCVSS 9.3EG 9.32024-03-04
Memory corruption in Core Services while executing the command for removing a single event listener.
- CVE-2023-2858MEDIUMCVSS 5.3EG 5.32023-05-26
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVE-2023-28580MEDIUMCVSS 6.7EG 6.72023-12-05
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
- CVE-2023-28581CRITICALCVSS 9.8EG 9.82023-09-05
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
- CVE-2023-28582CRITICALCVSS 9.8EG 9.82024-03-04
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
- CVE-2023-28587HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
- CVE-2023-28703HIGHCVSS 7.2EG 7.22023-06-02
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to exec…
- CVE-2023-28728HIGHCVSS 7.8EG 7.82023-07-21
A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.
- CVE-2023-2873MEDIUMCVSS 5.3EG 5.32023-05-24
A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation…
- CVE-2023-28730HIGHCVSS 7.8EG 7.82023-07-21
A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.
- CVE-2023-28753CRITICALCVSS 9.8EG 9.82023-05-18
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.
- CVE-2023-28793HIGHCVSS 7.8EG 7.82023-10-23
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- CVE-2023-28798MEDIUMCVSS 6.5EG 6.52024-05-02
An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.
- CVE-2023-28879CRITICALCVSS 9.8EG 9.82023-03-31
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write …
- CVE-2023-28885MEDIUMCVSS 6.8EG 6.82023-03-27
The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to cause a denial of service (temporary failure of Media Player functionality) via a crafted MP3 file.
- CVE-2023-2905HIGHCVSS 8.8EG 8.82023-08-09
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability …
- CVE-2023-29067HIGHCVSS 7.8EG 7.82023-04-14
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution…
- CVE-2023-29068HIGHCVSS 7.8EG 7.82023-06-27
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current proce…
- CVE-2023-29073CRITICALCVSS 9.8EG 9.82023-11-23
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…
- CVE-2023-29074CRITICALCVSS 9.8EG 9.82023-11-23
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrar…
- CVE-2023-29075CRITICALCVSS 9.8EG 9.82023-11-23
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary co…
- CVE-2023-29085MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-29086MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-29087MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-29088MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-29090MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-29091MEDIUMCVSS 6.8EG 6.82023-04-14
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficie…
- CVE-2023-2911HIGHCVSS 7.5EG 7.52023-06-21
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unex…
- CVE-2023-29125CRITICALCVSS 9.0EG 9.02024-11-05
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
- CVE-2023-29160HIGHCVSS 7.8EG 7.82023-06-13
Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code ma…
- CVE-2023-29182MEDIUMCVSS 6.4EG 6.42023-08-17
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack prote…
- CVE-2023-2923MEDIUMCVSS 6.3EG 6.32023-05-27
A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched r…
- CVE-2023-29276HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2023-29282HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2023-29283HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2023-29284HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2023-29285HIGHCVSS 7.8EG 7.82023-05-11
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2023-2929HIGHCVSS 8.8EG 8.82023-05-30
Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-29308HIGHCVSS 7.8EG 7.82023-07-12
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2023-2934HIGHCVSS 8.8EG 8.82023-05-30
Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-29416MEDIUMCVSS 6.5EG 6.52023-04-06
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3_decode_block out-of-bounds write can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
- CVE-2023-29421HIGHCVSS 8.8EG 8.82023-04-06
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3_decode_block.
- CVE-2023-29451MEDIUMCVSS 4.7EG 4.72023-07-13
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →