CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
15,227 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 2 of 305
- CVE-2024-4761CRITICALCVSS 8.8EG 9.0⚠ KEV2024-05-14
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-0519CRITICALCVSS 8.8EG 9.0⚠ KEV2024-01-16
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-7024CRITICALCVSS 8.8EG 9.0⚠ KEV2023-12-21
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-42917CRITICALCVSS 8.8EG 9.0⚠ KEV2023-11-30
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of …
- CVE-2023-5217CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-28
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-4863CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-12
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2023-32435CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-23
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execu…
- CVE-2022-41128CRITICALCVSS 8.8EG 9.0⚠ KEV2022-11-09
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2022-32893CRITICALCVSS 8.8EG 9.0⚠ KEV2022-08-24
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code exec…
- CVE-2022-2294CRITICALCVSS 8.8EG 9.0⚠ KEV2022-07-28
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-38003CRITICALCVSS 8.8EG 9.0⚠ KEV2021-11-23
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30632CRITICALCVSS 8.8EG 9.0⚠ KEV2021-10-08
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30665CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-08
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to…
- CVE-2021-30761CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-08
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have…
- CVE-2021-34448CRITICALCVSS 8.8EG 9.0⚠ KEV2021-07-16
Scripting Engine Memory Corruption Vulnerability
- CVE-2021-28664CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-10
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valh…
- CVE-2021-21220CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-26
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-26411CRITICALCVSS 8.8EG 9.0⚠ KEV2021-03-11
Internet Explorer Memory Corruption Vulnerability
- CVE-2021-21017CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-11
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vul…
- CVE-2021-21148CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-09
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-16013CRITICALCVSS 8.8EG 9.0⚠ KEV2021-01-08
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-16009CRITICALCVSS 8.8EG 9.0⚠ KEV2020-11-03
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-9818CRITICALCVSS 8.8EG 9.0⚠ KEV2020-06-09
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification …
- CVE-2020-1020CRITICALCVSS 8.8EG 9.0⚠ KEV2020-04-15
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an a…
- CVE-2020-5735CRITICALCVSS 8.8EG 9.0⚠ KEV2020-04-08
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
- CVE-2020-3118CRITICALCVSS 8.8EG 9.0⚠ KEV2020-02-05
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to impro…
- CVE-2019-13720CRITICALCVSS 8.8EG 9.0⚠ KEV2019-11-25
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-17480CRITICALCVSS 8.8EG 9.0⚠ KEV2018-12-11
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2018-6065CRITICALCVSS 8.8EG 9.0⚠ KEV2018-11-14
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-0798CRITICALCVSS 8.8EG 9.0⚠ KEV2018-01-10
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corru…
- CVE-2017-0222CRITICALCVSS 8.8EG 9.0⚠ KEV2017-05-12
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
- CVE-2017-0149CRITICALCVSS 8.8EG 9.0⚠ KEV2017-03-17
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability …
- CVE-2016-5198CRITICALCVSS 8.8EG 9.0⚠ KEV2017-01-19
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations…
- CVE-2016-7200CRITICALCVSS 8.8EG 9.0⚠ KEV2016-11-10
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a d…
- CVE-2016-4657CRITICALCVSS 8.8EG 9.0⚠ KEV2016-08-25
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
- CVE-2015-2502CRITICALCVSS 8.8EG 9.0⚠ KEV2015-08-19
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2…
- CVE-2015-2425CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability th…
- CVE-2015-2424CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corrupti…
- CVE-2015-2419CRITICALCVSS 8.8EG 9.0⚠ KEV2015-07-14
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
- CVE-2013-3918CRITICALCVSS 8.8EG 9.0⚠ KEV2013-11-12
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server…
- CVE-2013-3163CRITICALCVSS 8.8EG 9.0⚠ KEV2013-07-10
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2012-1889CRITICALCVSS 8.8EG 9.0⚠ KEV2012-06-13
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
- CVE-2009-3953CRITICALCVSS 8.8EG 9.0⚠ KEV2010-01-13
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODPr…
- CVE-2023-28206CRITICALCVSS 8.6EG 9.0⚠ KEV2023-04-10
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be …
- CVE-2018-0172CRITICALCVSS 8.6EG 9.0⚠ KEV2018-03-28
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS)…
- CVE-2021-22555CRITICALCVSS 8.3EG 9.0⚠ KEV2021-07-07
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
- CVE-2025-22225CRITICALCVSS 8.2EG 9.0⚠ KEV2025-03-04
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
- CVE-2025-27363CRITICALCVSS 8.1EG 9.0⚠ KEV2025-03-11
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assig…
- CVE-2020-6819CRITICALCVSS 8.1EG 9.0⚠ KEV2020-04-24
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.…
- CVE-2012-0754CRITICALCVSS 8.1EG 9.0⚠ KEV2012-02-16
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause …
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →