CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,923 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 190 of 279
- CVE-2023-34318HIGHCVSS 7.8EG 7.82023-07-10
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
- CVE-2023-34319HIGHCVSS 7.8EG 7.82023-09-22
The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the logic introduced there didn't account for the extre…
- CVE-2023-34325HIGHCVSS 7.8EG 7.82024-01-05
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains parsing code for several filesystems, most of them based on grub-legacy code. libfsimag…
- CVE-2023-34346CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger t…
- CVE-2023-34351HIGHCVSS 7.5EG 7.52024-02-14
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2023-34364CRITICALCVSS 9.8EG 9.82023-06-09
A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allo…
- CVE-2023-34365CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to tr…
- CVE-2023-34402HIGHCVSS 7.7EG 7.72025-02-13
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. Due to missed checks, attacker can achieve Arbitrary File Wr…
- CVE-2023-34416CRITICALCVSS 9.8EG 9.82023-06-19
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary …
- CVE-2023-34417CRITICALCVSS 9.8EG 9.82023-06-19
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 1…
- CVE-2023-34426CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request …
- CVE-2023-34432HIGHCVSS 7.8EG 7.82023-07-10
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
- CVE-2023-34436HIGHCVSS 7.8EG 7.82024-01-08
An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger t…
- CVE-2023-34474MEDIUMCVSS 5.5EG 5.52023-06-16
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an …
- CVE-2023-34488HIGHCVSS 7.8EG 7.82023-06-12
NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
- CVE-2023-34551HIGHCVSS 8.0EG 8.02023-08-01
In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server can allow an authenticated attacker present on the same local network as the camera to achieve remote code execution. Thi…
- CVE-2023-34552HIGHCVSS 8.8EG 8.82023-08-01
In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol can allow an unauthenticated attacker present on the same local network as the ca…
- CVE-2023-34566CRITICALCVSS 9.8EG 9.82023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.
- CVE-2023-34567MEDIUMCVSS 6.7EG 6.72023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
- CVE-2023-34568MEDIUMCVSS 6.7EG 6.72023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
- CVE-2023-34569MEDIUMCVSS 6.7EG 6.72023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.
- CVE-2023-34570MEDIUMCVSS 6.7EG 6.72023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.
- CVE-2023-34571MEDIUMCVSS 6.7EG 6.72023-06-08
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.
- CVE-2023-34609HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered flexjson thru 3.3 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34610HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34611HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34612HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34613HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered sojo thru 1.1.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34614HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34615HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34616HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34617HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34620HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34623HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34624HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-3463MEDIUMCVSS 6.6EG 6.62023-07-19
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bo…
- CVE-2023-34823MEDIUMCVSS 5.5EG 5.52023-06-14
fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.
- CVE-2023-34824MEDIUMCVSS 5.5EG 5.52023-06-14
fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c.
- CVE-2023-34853HIGHCVSS 7.8EG 7.82023-08-22
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
- CVE-2023-3487HIGHCVSS 7.7EG 7.72023-10-20
An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.
- CVE-2023-34924HIGHCVSS 7.5EG 7.52023-06-26
H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34928HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34929HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34930HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34931HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34932HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34933HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34934HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34935HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2023-34936HIGHCVSS 7.5EG 7.52023-06-28
A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →