CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
13,926 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 203 of 279
- CVE-2023-42871HIGHCVSS 7.8EG 7.82024-01-10
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-42873HIGHCVSS 7.8EG 7.82024-02-21
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. An app may be able to execute ar…
- CVE-2023-42882HIGHCVSS 7.8EG 7.82023-12-12
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.
- CVE-2023-42901HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42902HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42903HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42904HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42905HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42906HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42907HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42908HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42909HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42910HIGHCVSS 8.8EG 8.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42911HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42912HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-42917HIGHCVSS 8.8EG 9.0⚠ KEV2023-11-30
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of …
- CVE-2023-42926HIGHCVSS 7.8EG 7.82023-12-12
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-43010HIGHCVSS 8.8EG 8.82026-03-12
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web conten…
- CVE-2023-43122MEDIUMCVSS 4.6EG 4.82023-12-13
Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.
- CVE-2023-43196CRITICALCVSS 9.8EG 9.82023-09-20
D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.
- CVE-2023-43197CRITICALCVSS 9.8EG 9.82023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.
- CVE-2023-43198CRITICALCVSS 9.8EG 9.82023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.
- CVE-2023-43199CRITICALCVSS 9.8EG 9.82023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.
- CVE-2023-43200CRITICALCVSS 9.8EG 9.82023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.
- CVE-2023-43201CRITICALCVSS 9.8EG 9.82023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.
- CVE-2023-43203CRITICALCVSS 9.8EG 9.82023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.
- CVE-2023-4322CRITICALCVSS 9.8EG 9.82023-08-14
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
- CVE-2023-43235CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.
- CVE-2023-43236CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.
- CVE-2023-43237CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.
- CVE-2023-43238CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.
- CVE-2023-43239CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.
- CVE-2023-43240CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.
- CVE-2023-43241CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
- CVE-2023-43242CRITICALCVSS 9.8EG 9.82023-09-21
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.
- CVE-2023-43252HIGHCVSS 7.8EG 7.82023-10-19
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.
- CVE-2023-43338CRITICALCVSS 9.8EG 9.82023-09-23
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.
- CVE-2023-43361HIGHCVSS 7.8EG 7.82023-10-02
Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
- CVE-2023-43492CRITICALCVSS 9.8EG 9.82023-10-19
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
- CVE-2023-43513HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- CVE-2023-43516HIGHCVSS 7.8EG 7.82024-02-06
Memory corruption when malformed message payload is received from firmware.
- CVE-2023-43517HIGHCVSS 8.4EG 8.42024-02-06
Memory corruption in Automotive Multimedia due to improper access control in HAB.
- CVE-2023-43518HIGHCVSS 7.3EG 7.32024-02-06
Memory corruption in video while parsing invalid mp2 clip.
- CVE-2023-43520HIGHCVSS 8.6EG 8.62024-02-06
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
- CVE-2023-4353HIGHCVSS 8.8EG 8.82023-08-15
Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-4354HIGHCVSS 8.8EG 8.82023-08-15
Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-43540HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption while processing the IOCTL FM HCI WRITE request.
- CVE-2023-43548HIGHCVSS 7.3EG 7.32024-03-04
Memory corruption while parsing qcp clip with invalid chunk data size.
- CVE-2023-43549HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption while processing TPC target power table in FTM TPC.
- CVE-2023-4355HIGHCVSS 8.8EG 8.82023-08-15
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →