CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,922 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 184 of 279
- CVE-2023-29462HIGHCVSS 7.8EG 7.82023-05-09
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffe…
- CVE-2023-29464HIGHCVSS 8.2EG 8.22023-10-13
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory …
- CVE-2023-29491HIGHCVSS 7.8EG 7.82023-04-14
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO o…
- CVE-2023-29531CRITICALCVSS 9.8EG 9.82023-06-19
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffe…
- CVE-2023-29551HIGHCVSS 8.8EG 8.82023-06-02
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for…
- CVE-2023-29562CRITICALCVSS 9.8EG 9.82023-06-13
TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.
- CVE-2023-29578HIGHCVSS 8.8EG 8.82023-04-24
mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp.
- CVE-2023-29579MEDIUMCVSS 5.5EG 7.82023-04-24
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone p…
- CVE-2023-29582MEDIUMCVSS 5.5EG 7.82023-04-24
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone…
- CVE-2023-29583MEDIUMCVSS 5.5EG 7.82023-04-24
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone…
- CVE-2023-29584HIGHCVSS 8.8EG 8.82023-04-14
mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp.
- CVE-2023-29665CRITICALCVSS 9.8EG 9.82023-04-17
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
- CVE-2023-29693CRITICALCVSS 9.8EG 9.82023-05-08
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad.
- CVE-2023-29696CRITICALCVSS 9.8EG 9.82023-05-08
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.
- CVE-2023-29905MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.
- CVE-2023-29906MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm.
- CVE-2023-29907MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm.
- CVE-2023-29908MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm.
- CVE-2023-29909MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm.
- CVE-2023-29910MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm.
- CVE-2023-29911MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.
- CVE-2023-29912MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.
- CVE-2023-29913MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm.
- CVE-2023-29914MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
- CVE-2023-29915MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.
- CVE-2023-29916MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.
- CVE-2023-29917MEDIUMCVSS 4.9EG 4.92023-04-21
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via go parameter at /goform/aspForm.
- CVE-2023-29929HIGHCVSS 7.5EG 7.52024-08-21
Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.
- CVE-2023-29950MEDIUMCVSS 5.5EG 5.52023-04-27
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c
- CVE-2023-29961CRITICALCVSS 9.8EG 9.82023-05-16
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
- CVE-2023-29994HIGHCVSS 7.5EG 7.52023-05-04
In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.
- CVE-2023-29995HIGHCVSS 7.5EG 7.52023-05-04
In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c
- CVE-2023-30086MEDIUMCVSS 5.5EG 5.52023-05-09
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
- CVE-2023-30087MEDIUMCVSS 5.5EG 5.52023-05-09
Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.
- CVE-2023-30187CRITICALCVSS 9.8EG 9.82023-08-14
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
- CVE-2023-3024MEDIUMCVSS 5.9EG 5.92023-09-29
Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.
- CVE-2023-30368CRITICALCVSS 9.8EG 9.82023-04-24
Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.
- CVE-2023-30369CRITICALCVSS 9.8EG 9.82023-04-24
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
- CVE-2023-30370CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
- CVE-2023-30371CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30372CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30373CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30375CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30376CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30378CRITICALCVSS 9.8EG 9.82023-04-24
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
- CVE-2023-30382HIGHCVSS 7.3EG 7.32023-05-23
A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supplying crafted parameters.
- CVE-2023-30402MEDIUMCVSS 5.5EG 5.52023-04-25
YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone pro…
- CVE-2023-30410MEDIUMCVSS 5.5EG 5.52023-04-24
Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /operations/ecma-function-object.c.
- CVE-2023-30414MEDIUMCVSS 5.5EG 5.52023-04-24
Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.
- CVE-2023-3043CRITICALCVSS 9.6EG 9.62024-01-09
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, a…
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →