CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 199 of 279
- CVE-2023-41559CRITICALCVSS 9.8EG 9.82023-08-30
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.
- CVE-2023-41560CRITICALCVSS 9.8EG 9.82023-08-30
Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.
- CVE-2023-41561CRITICALCVSS 9.8EG 9.82023-08-30
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.
- CVE-2023-41562CRITICALCVSS 9.8EG 9.82023-08-30
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.
- CVE-2023-41563CRITICALCVSS 9.8EG 9.82023-08-30
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.
- CVE-2023-41711MEDIUMCVSS 6.5EG 6.52023-10-17
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.
- CVE-2023-41712MEDIUMCVSS 6.5EG 6.52023-10-17
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.
- CVE-2023-41727CRITICALCVSS 9.8EG 9.82023-12-19
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
- CVE-2023-42043HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required t…
- CVE-2023-42047HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required t…
- CVE-2023-42051HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required…
- CVE-2023-42069HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is …
- CVE-2023-42071HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required…
- CVE-2023-42076HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is r…
- CVE-2023-42077HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor EMF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is r…
- CVE-2023-42078HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required t…
- CVE-2023-42083HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor JPG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is r…
- CVE-2023-42085HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor EMF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is r…
- CVE-2023-42115CRITICALCVSS 9.8EG 9.82024-05-03
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The …
- CVE-2023-42127HIGHCVSS 7.8EG 7.82024-05-03
Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to ex…
- CVE-2023-42131HIGHCVSS 7.8EG 7.82024-05-03
Ansys SpaceClaim X_B File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim. User interaction is required to …
- CVE-2023-42366MEDIUMCVSS 5.5EG 5.52023-11-27
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
- CVE-2023-42443HIGHCVSS 8.1EG 8.12023-09-18
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corru…
- CVE-2023-42507HIGHCVSS 7.8EG 7.82023-10-17
Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinVi…
- CVE-2023-42528HIGHCVSS 7.8EG 7.82023-11-07
Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-42529HIGHCVSS 7.8EG 7.82023-11-07
Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-42535HIGHCVSS 7.8EG 7.82023-11-07
Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
- CVE-2023-42536HIGHCVSS 7.8EG 9.82023-11-07
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- CVE-2023-42537HIGHCVSS 7.8EG 9.82023-11-07
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- CVE-2023-42538HIGHCVSS 7.8EG 9.82023-11-07
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- CVE-2023-4255MEDIUMCVSS 5.5EG 5.52023-12-21
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Explo…
- CVE-2023-42557MEDIUMCVSS 6.7EG 6.72023-12-05
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
- CVE-2023-42558HIGHCVSS 7.8EG 7.82023-12-05
Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
- CVE-2023-42560HIGHCVSS 7.8EG 7.82023-12-05
Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
- CVE-2023-42561MEDIUMCVSS 6.8EG 7.12023-12-05
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
- CVE-2023-42566HIGHCVSS 7.8EG 7.82023-12-05
Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-42567HIGHCVSS 7.8EG 7.82023-12-05
Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
- CVE-2023-42653MEDIUMCVSS 5.5EG 5.52023-11-01
In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges
- CVE-2023-42679MEDIUMCVSS 4.4EG 4.42023-12-04
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-42682MEDIUMCVSS 4.4EG 4.42023-12-04
In gsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-42727MEDIUMCVSS 4.4EG 4.42023-12-04
In gpu driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-42729MEDIUMCVSS 4.4EG 4.42023-12-04
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-4273MEDIUMCVSS 6.7EG 6.72023-08-09
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file n…
- CVE-2023-42750MEDIUMCVSS 4.4EG 4.42023-11-01
In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-42751MEDIUMCVSS 4.4EG 4.42023-12-04
In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- CVE-2023-42753HIGHCVSS 7.8EG 7.82023-09-25
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decreme…
- CVE-2023-42789CRITICALCVSS 9.8EG 9.82024-03-12
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through …
- CVE-2023-4280CRITICALCVSS 9.8EG 9.82024-01-02
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
- CVE-2023-42848HIGHCVSS 7.8EG 7.82024-02-21
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. Processing a maliciously crafted image ma…
- CVE-2023-42869HIGHCVSS 7.5EG 7.52024-01-10
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues in libxml2.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →