CWE-787— Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.— MITRE CWE catalog
15,227 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-787page 3 of 305
- CVE-2026-53362CRITICALCVSS 7.8EG 9.0⚠ KEV2026-07-04
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), allocle…
- CVE-2024-53197CRITICALCVSS 7.8EG 9.0⚠ KEV2024-12-27
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value use…
- CVE-2024-53104CRITICALCVSS 7.8EG 9.0⚠ KEV2024-12-02
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into acc…
- CVE-2024-30051CRITICALCVSS 7.8EG 9.0⚠ KEV2024-05-14
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2024-23296CRITICALCVSS 7.8EG 9.0⚠ KEV2024-03-05
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watch…
- CVE-2024-23225CRITICALCVSS 7.8EG 9.0⚠ KEV2024-03-05
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watch…
- CVE-2023-36036CRITICALCVSS 7.8EG 9.0⚠ KEV2023-11-14
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-4911CRITICALCVSS 7.8EG 9.0⚠ KEV2023-10-03
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables …
- CVE-2023-26369CRITICALCVSS 7.8EG 9.0⚠ KEV2023-09-13
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …
- CVE-2023-28252CRITICALCVSS 7.8EG 9.0⚠ KEV2023-04-11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-23376CRITICALCVSS 7.8EG 9.0⚠ KEV2023-02-14
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-41125CRITICALCVSS 7.8EG 9.0⚠ KEV2022-11-09
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2022-41073CRITICALCVSS 7.8EG 9.0⚠ KEV2022-11-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-42827CRITICALCVSS 7.8EG 9.0⚠ KEV2022-11-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aw…
- CVE-2022-32917CRITICALCVSS 7.8EG 9.0⚠ KEV2022-09-20
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aw…
- CVE-2022-37969CRITICALCVSS 7.8EG 9.0⚠ KEV2022-09-13
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-32894CRITICALCVSS 7.8EG 9.0⚠ KEV2022-08-24
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is awa…
- CVE-2022-22675CRITICALCVSS 7.8EG 9.0⚠ KEV2022-05-26
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbit…
- CVE-2022-24521CRITICALCVSS 7.8EG 9.0⚠ KEV2022-04-15
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-0995CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-25
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a …
- CVE-2021-39793CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-16
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2021-4034CRITICALCVSS 7.8EG 9.0⚠ KEV2022-01-28
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current ve…
- CVE-2022-21882CRITICALCVSS 7.8EG 9.0⚠ KEV2022-01-11
Win32k Elevation of Privilege Vulnerability
- CVE-2021-30807CRITICALCVSS 7.8EG 9.0⚠ KEV2021-10-19
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. A…
- CVE-2021-38406CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-17
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerab…
- CVE-2021-30900CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-24
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges.
- CVE-2021-30883CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-24
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application m…
- CVE-2020-11261CRITICALCVSS 7.8EG 9.0⚠ KEV2021-06-09
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sn…
- CVE-2021-28310CRITICALCVSS 7.8EG 9.0⚠ KEV2021-04-13
Win32k Elevation of Privilege Vulnerability
- CVE-2021-1732CRITICALCVSS 7.8EG 9.0⚠ KEV2021-02-25
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2021-3156CRITICALCVSS 7.8EG 9.0⚠ KEV2021-01-26
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- CVE-2020-27930CRITICALCVSS 7.8EG 9.0⚠ KEV2020-12-08
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 an…
- CVE-2020-9907CRITICALCVSS 7.8EG 9.0⚠ KEV2020-10-16
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
- CVE-2020-1380CRITICALCVSS 7.8EG 9.0⚠ KEV2020-08-17
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the con…
- CVE-2020-0986CRITICALCVSS 7.8EG 9.0⚠ KEV2020-06-09
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020…
- CVE-2020-1054CRITICALCVSS 7.8EG 9.0⚠ KEV2020-05-21
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An…
- CVE-2020-1027CRITICALCVSS 7.8EG 9.0⚠ KEV2020-04-15
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.
- CVE-2020-0938CRITICALCVSS 7.8EG 9.0⚠ KEV2020-04-15
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an a…
- CVE-2020-0069CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-10
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additiona…
- CVE-2020-0041CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-10
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2020-3837CRITICALCVSS 7.8EG 9.0⚠ KEV2020-02-27
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kerne…
- CVE-2019-7287CRITICALCVSS 7.8EG 9.0⚠ KEV2019-12-18
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
- CVE-2019-7286CRITICALCVSS 7.8EG 9.0⚠ KEV2019-12-18
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
- CVE-2018-0802CRITICALCVSS 7.8EG 9.0⚠ KEV2018-01-10
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corrup…
- CVE-2017-8540CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-26
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 15…
- CVE-2016-4656CRITICALCVSS 7.8EG 9.0⚠ KEV2016-08-25
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
- CVE-2015-1642CRITICALCVSS 7.8EG 9.0⚠ KEV2015-08-15
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
- CVE-2015-2387CRITICALCVSS 7.8EG 9.0⚠ KEV2015-07-14
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.…
- CVE-2015-1641CRITICALCVSS 7.8EG 9.0⚠ KEV2015-04-14
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 201…
- CVE-2014-4404CRITICALCVSS 7.8EG 9.0⚠ KEV2014-09-18
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
Map vulnerabilities like CWE-787 to your infrastructure
EchelonGraph correlates every CVE — across CWE-787 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →