CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,923 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 192 of 279
- CVE-2023-35788HIGHCVSS 7.8EG 7.82023-06-16
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial o…
- CVE-2023-35871HIGHCVSS 7.7EG 7.72023-07-11
The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.91, KERNEL 7.92, KER…
- CVE-2023-35949HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabil…
- CVE-2023-3595CRITICALCVSS 9.8EG 9.82023-07-12
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through malicio…
- CVE-2023-35950HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabil…
- CVE-2023-35951HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabil…
- CVE-2023-35952HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabil…
- CVE-2023-35953HIGHCVSS 7.8EG 7.82024-05-28
Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabil…
- CVE-2023-3596HIGHCVSS 7.5EG 7.52023-07-12
Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.…
- CVE-2023-35965CRITICALCVSS 9.8EG 9.82023-10-11
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to tri…
- CVE-2023-35966CRITICALCVSS 9.8EG 9.82023-10-11
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to tri…
- CVE-2023-35967CRITICALCVSS 9.8EG 9.82023-10-11
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network r…
- CVE-2023-35968CRITICALCVSS 9.8EG 9.82023-10-11
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network r…
- CVE-2023-35969HIGHCVSS 7.8EG 7.82024-01-08
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a m…
- CVE-2023-35970HIGHCVSS 7.8EG 7.82024-01-08
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a m…
- CVE-2023-3598HIGHCVSS 8.8EG 8.82023-07-28
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-35984MEDIUMCVSS 4.3EG 4.32023-09-27
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An attacker in physical proximity can cause a limited out of bounds write.
- CVE-2023-35986HIGHCVSS 7.8EG 7.82023-10-19
Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the…
- CVE-2023-36017HIGHCVSS 8.8EG 8.82023-11-14
Windows Scripting Engine Memory Corruption Vulnerability
- CVE-2023-36036HIGHCVSS 7.8EG 9.0⚠ KEV2023-11-14
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-3611HIGHCVSS 7.8EG 7.82023-07-21
An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lma…
- CVE-2023-36184HIGHCVSS 7.5EG 7.52023-09-08
CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.
- CVE-2023-36192HIGHCVSS 7.8EG 7.82023-06-23
Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c.
- CVE-2023-36193HIGHCVSS 7.8EG 7.82023-06-23
Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.
- CVE-2023-36271HIGHCVSS 8.8EG 8.82023-06-23
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
- CVE-2023-36272HIGHCVSS 8.8EG 8.82023-06-23
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
- CVE-2023-36273HIGHCVSS 8.8EG 8.82023-06-23
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
- CVE-2023-36274HIGHCVSS 8.8EG 8.82023-06-23
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
- CVE-2023-3633HIGHCVSS 8.1EG 8.12023-07-14
An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.94791 and lower.
- CVE-2023-36340CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
- CVE-2023-36532MEDIUMCVSS 5.9EG 5.92023-08-08
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
- CVE-2023-36660CRITICALCVSS 9.8EG 9.82023-06-25
The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
- CVE-2023-36746HIGHCVSS 7.0EG 7.02024-01-08
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file…
- CVE-2023-36747HIGHCVSS 7.0EG 7.02024-01-08
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file…
- CVE-2023-36824HIGHCVSS 7.4EG 8.82023-07-11
Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corr…
- CVE-2023-36861HIGHCVSS 7.8EG 7.82024-01-08
An out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vuln…
- CVE-2023-36947CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
- CVE-2023-36950CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
- CVE-2023-36952CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.
- CVE-2023-36955CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
- CVE-2023-37032HIGHCVSS 7.5EG 7.52025-01-21
A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by se…
- CVE-2023-37139MEDIUMCVSS 5.5EG 5.52023-07-18
ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray().
- CVE-2023-37174MEDIUMCVSS 5.5EG 5.52023-07-11
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.
- CVE-2023-37211HIGHCVSS 8.8EG 8.82023-07-05
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary …
- CVE-2023-37212HIGHCVSS 8.8EG 8.82023-07-05
Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 1…
- CVE-2023-37246HIGHCVSS 7.8EG 7.82023-07-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while…
- CVE-2023-37247HIGHCVSS 7.8EG 7.82023-07-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while…
- CVE-2023-37248HIGHCVSS 7.8EG 7.82023-07-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application contains an out of bounds write past the end of a…
- CVE-2023-3725HIGHCVSS 7.6EG 7.62023-10-06
Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
- CVE-2023-37282HIGHCVSS 7.8EG 7.82024-01-08
An out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →