CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,922 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 185 of 279
- CVE-2023-30644HIGHCVSS 7.8EG 7.82023-07-06
Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
- CVE-2023-30645HIGHCVSS 7.8EG 7.82023-07-06
Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
- CVE-2023-30646HIGHCVSS 7.8EG 7.82023-07-06
Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
- CVE-2023-30647HIGHCVSS 7.8EG 7.82023-07-06
Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
- CVE-2023-30648LOWCVSS 3.3EG 3.32023-07-06
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
- CVE-2023-30649HIGHCVSS 7.8EG 7.82023-07-06
Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
- CVE-2023-30650MEDIUMCVSS 6.7EG 6.72023-07-06
Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-30651MEDIUMCVSS 6.7EG 6.72023-07-06
Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-30652MEDIUMCVSS 6.7EG 6.72023-07-06
Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-30653MEDIUMCVSS 6.7EG 6.72023-07-06
Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-30666MEDIUMCVSS 5.3EG 5.32023-07-06
Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
- CVE-2023-30668MEDIUMCVSS 6.7EG 6.72023-07-06
Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30669MEDIUMCVSS 6.7EG 6.72023-07-06
Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30670MEDIUMCVSS 6.7EG 6.72023-07-06
Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30681MEDIUMCVSS 4.4EG 4.42023-08-10
An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- CVE-2023-30686MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30687MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30688MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30689MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30693MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30694MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-30695MEDIUMCVSS 6.7EG 6.72023-08-10
Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allo…
- CVE-2023-30696MEDIUMCVSS 4.4EG 4.42023-08-10
An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- CVE-2023-30697MEDIUMCVSS 4.4EG 4.42023-08-10
An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- CVE-2023-30699HIGHCVSS 7.5EG 7.52023-08-10
Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
- CVE-2023-30702MEDIUMCVSS 6.7EG 6.72023-08-10
Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows lo…
- CVE-2023-30733HIGHCVSS 7.8EG 7.82023-10-04
Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.
- CVE-2023-30763HIGHCVSS 7.2EG 7.22023-05-12
Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-30770HIGHCVSS 7.1EG 9.82023-04-17
A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2…
- CVE-2023-30774MEDIUMCVSS 5.5EG 5.52023-05-19
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
- CVE-2023-30775MEDIUMCVSS 5.5EG 5.52023-05-19
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
- CVE-2023-30800HIGHCVSS 7.5EG 7.52023-09-07
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface …
- CVE-2023-3090HIGHCVSS 7.8EG 7.82023-06-28
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. …
- CVE-2023-30986HIGHCVSS 7.8EG 7.82023-05-09
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain a memory corruption vulnerability while parsing specially crafted …
- CVE-2023-31024CRITICALCVSS 9.0EG 9.02024-01-12
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to …
- CVE-2023-31029CRITICALCVSS 9.3EG 9.32024-01-12
NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this…
- CVE-2023-31030CRITICALCVSS 9.3EG 9.32024-01-12
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitra…
- CVE-2023-31031MEDIUMCVSS 4.2EG 4.22024-01-12
NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, info…
- CVE-2023-31096HIGHCVSS 7.8EG 7.82023-10-10
An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit…
- CVE-2023-3110CRITICALCVSS 9.6EG 9.62023-06-21
Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
- CVE-2023-31130MEDIUMCVSS 4.1EG 4.12023-05-25
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for conf…
- CVE-2023-31146HIGHCVSS 7.5EG 7.52023-05-11
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, the length word of a dynarray is written before the data, which can result in out-of-bounds array access in the case wher…
- CVE-2023-31194MEDIUMCVSS 5.3EG 5.32023-07-05
An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger th…
- CVE-2023-31247CRITICALCVSS 9.0EG 9.02023-11-14
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to tr…
- CVE-2023-31272HIGHCVSS 8.8EG 8.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigg…
- CVE-2023-31284HIGHCVSS 7.8EG 7.82023-05-04
illumos illumos-gate before 676abcb has a stack buffer overflow in /dev/net, leading to privilege escalation via a stat on a long file name in /dev/net.
- CVE-2023-31355MEDIUMCVSS 6.0EG 6.02024-08-05
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
- CVE-2023-3138HIGHCVSS 7.5EG 7.52023-06-28
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functi…
- CVE-2023-31419MEDIUMCVSS 6.5EG 7.92023-10-26
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
- CVE-2023-31436HIGHCVSS 7.8EG 7.82023-04-28
qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →