CWE-788— Access of Memory Location After End of Buffer
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.— MITRE CWE catalog
168 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-788page 1 of 4
- CVE-2021-27384CRITICALCVSS 9.8EG 9.82021-05-12
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16…
- CVE-2019-8280CRITICALCVSS 9.8EG 9.82019-03-08
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This attack appear to be exploitable via network connectivity. This vulnerability has been fixed i…
- CVE-2019-8266CRITICALCVSS 9.8EG 9.82019-03-08
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnection::Copybuffer function in VNC client code, which can potentially result in code execution. This attack appears to be e…
- CVE-2019-8265CRITICALCVSS 9.8EG 9.82019-03-08
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network…
- CVE-2019-8264CRITICALCVSS 9.8EG 9.82019-03-08
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been …
- CVE-2024-29176HIGHCVSS 8.8EG 8.82024-06-26
Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
- CVE-2021-21105HIGHCVSS 8.8EG 8.82021-09-08
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the cont…
- CVE-2021-21104HIGHCVSS 8.8EG 8.82021-09-08
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of t…
- CVE-2021-28561HIGHCVSS 8.8EG 8.82021-09-02
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerabilit…
- CVE-2021-39820HIGHCVSS 7.8EG 8.82022-06-15
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of…
- CVE-2021-21103HIGHCVSS 4.3EG 8.82021-09-08
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in …
- CVE-2024-20402HIGHCVSS 8.6EG 8.62024-10-23
A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedl…
- CVE-2024-20330HIGHCVSS 7.5EG 8.62024-10-23
A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption,…
- CVE-2023-22297HIGHCVSS 8.2EG 8.22023-05-10
Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
- CVE-2026-25584HIGHCVSS 7.8EG 7.82026-02-04
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::Get…
- CVE-2024-27828HIGHCVSS 7.8EG 7.82024-06-10
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2024-27829HIGHCVSS 7.8EG 7.82024-05-14
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
- CVE-2024-0229HIGHCVSS 7.8EG 7.82024-02-09
An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege esc…
- CVE-2021-43755HIGHCVSS 7.8EG 7.82022-06-15
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of…
- CVE-2021-42735HIGHCVSS 7.8EG 7.82022-06-15
Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is…
- CVE-2021-43756HIGHCVSS 7.8EG 7.82022-06-15
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current u…
- CVE-2021-43754HIGHCVSS 7.8EG 7.82022-06-15
Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-42732HIGHCVSS 7.8EG 7.82022-06-15
Access of Memory Location After End of Buffer (CWE-788)
- CVE-2021-40727HIGHCVSS 7.8EG 7.82022-06-15
Access of Memory Location After End of Buffer (CWE-788
- CVE-2021-46818HIGHCVSS 7.8EG 7.82022-06-13
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploit…
- CVE-2021-46817HIGHCVSS 7.8EG 7.82022-06-13
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploit…
- CVE-2021-46816HIGHCVSS 7.8EG 7.82022-06-13
Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploita…
- CVE-2021-42730HIGHCVSS 7.8EG 7.82022-03-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PSD file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-42729HIGHCVSS 7.8EG 7.82022-03-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-42724HIGHCVSS 7.8EG 7.82022-03-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction…
- CVE-2021-42527HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current use…
- CVE-2021-42526HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current use…
- CVE-2021-40794HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inter…
- CVE-2021-40793HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inter…
- CVE-2021-40792HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inter…
- CVE-2021-40787HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current use…
- CVE-2021-40786HIGHCVSS 7.8EG 7.82022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current use…
- CVE-2021-40780HIGHCVSS 7.8EG 7.82022-03-16
Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inte…
- CVE-2021-40779HIGHCVSS 7.8EG 7.82022-03-16
Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inte…
- CVE-2021-40777HIGHCVSS 7.8EG 7.82022-03-16
Adobe Media Encoder version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User inte…
- CVE-2021-40765HIGHCVSS 7.8EG 7.82022-03-16
Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required…
- CVE-2021-40764HIGHCVSS 7.8EG 7.82022-03-16
Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required…
- CVE-2021-40763HIGHCVSS 7.8EG 7.82022-03-16
Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a WAF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required…
- CVE-2021-40740HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to explo…
- CVE-2021-40739HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to explo…
- CVE-2021-40738HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to explo…
- CVE-2021-40736HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
- CVE-2021-40735HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
- CVE-2021-40734HIGHCVSS 7.8EG 7.82022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to explo…
- CVE-2021-44179HIGHCVSS 7.8EG 7.82021-12-20
Adobe Dimension versions 3.4.3 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User inte…
Map vulnerabilities like CWE-788 to your infrastructure
EchelonGraph correlates every CVE — across CWE-788 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →