CWE-788— Access of Memory Location After End of Buffer
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.— MITRE CWE catalog
168 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-788page 2 of 4
- CVE-2021-43747HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43029HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43028HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43026HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43025HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43024HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43023HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EPS/TIFF file, potentially resulting in arbitrary code execution in the context of the current user. …
- CVE-2021-43022HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PNG file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43021HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40784HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40783HIGHCVSS 7.8EG 7.82021-12-20
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-43015HIGHCVSS 7.8EG 7.82021-11-22
Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interacti…
- CVE-2021-42738HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-42737HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-40775HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-40772HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-40771HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-40770HIGHCVSS 7.8EG 7.82021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-42267HIGHCVSS 7.8EG 7.82021-11-18
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User intera…
- CVE-2021-42266HIGHCVSS 7.8EG 7.82021-11-18
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User intera…
- CVE-2021-40760HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User…
- CVE-2021-40759HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User…
- CVE-2021-40758HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40757HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40755HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SGI file in the DoReadContinue function, potentially resulting in arbitrary code execution in the con…
- CVE-2021-40754HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40753HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User …
- CVE-2021-40752HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User i…
- CVE-2021-40751HIGHCVSS 7.8EG 7.82021-11-18
Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User i…
- CVE-2021-40733HIGHCVSS 7.8EG 7.82021-11-18
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User inter…
- CVE-2021-43012HIGHCVSS 7.8EG 7.82021-11-16
Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation …
- CVE-2021-43011HIGHCVSS 7.8EG 7.82021-11-16
Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation …
- CVE-2021-42725HIGHCVSS 7.8EG 7.82021-11-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-42723HIGHCVSS 7.8EG 7.82021-11-16
Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulne…
- CVE-2021-43013HIGHCVSS 7.8EG 7.82021-11-16
Adobe Media Encoder version 15.4.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Explo…
- CVE-2021-42726HIGHCVSS 7.8EG 7.82021-11-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-40715HIGHCVSS 7.8EG 7.82021-09-29
Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .exr file, potentially resulting in arbitrary code execution in the context of the current user. User in…
- CVE-2021-40710HIGHCVSS 7.8EG 7.82021-09-29
Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User in…
- CVE-2021-39832HIGHCVSS 7.8EG 7.82021-09-29
Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious PDF file, potentially resulting in arbitrary code execu…
- CVE-2021-39830HIGHCVSS 7.8EG 7.82021-09-29
Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious PDF file, potentially resulting in arbitrary code execu…
- CVE-2021-40703HIGHCVSS 7.8EG 7.82021-09-27
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current u…
- CVE-2021-40702HIGHCVSS 7.8EG 7.82021-09-27
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current u…
- CVE-2021-40701HIGHCVSS 7.8EG 7.82021-09-27
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current u…
- CVE-2021-40700HIGHCVSS 7.8EG 7.82021-09-27
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current …
- CVE-2021-39824HIGHCVSS 7.8EG 7.82021-09-27
Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious png file, potentially resulting in arbitrary code execution in the context of the current u…
- CVE-2021-39819HIGHCVSS 7.8EG 7.82021-09-27
Adobe InCopy version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious XML file, potentially resulting in arbitrary code execution in the context of the current user. User interacti…
- CVE-2021-39818HIGHCVSS 7.8EG 7.82021-09-27
Adobe InCopy version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interact…
- CVE-2021-36017HIGHCVSS 7.8EG 7.82021-09-02
Adobe After Effects version 18.2.1 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in t…
- CVE-2021-35996HIGHCVSS 7.8EG 7.82021-09-02
Adobe After Effects version 18.2.1 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in t…
- CVE-2021-39817HIGHCVSS 7.8EG 7.82021-09-01
Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User intera…
Map vulnerabilities like CWE-788 to your infrastructure
EchelonGraph correlates every CVE — across CWE-788 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →