CWE-787
14,779 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,779)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges ne...Show more |
In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. Us...Show more |
In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges need...Show more |
An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. |
2Siemens Windriver36Ruggedcom Win Subscriber Station Firmware Scalance X200 4 P Irt FirmwareScalance X201 3p Irt Firmware+33 moreJun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
1Fortinet 2Fortios FortiproxyJun 17, 2026 Apr 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to cra...Show more |
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safet...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Apr 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Apr 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process. |
4Debian Exiv2Fedoraproject+1 more4Debian Linux Enterprise LinuxExiv2+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a cra...Show more |
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoCont...Show more |
D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulne...Show more |
1Qualcomm 54Aqt1000 Firmware Pm8005 FirmwarePm855 Firmware+51 moreJun 17, 2026 Apr 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Wired Infrastru...Show more |
1Qualcomm 170Csrb31024 Firmware Pm3003a FirmwarePm6150a Firmware+167 moreJun 17, 2026 Apr 7, 2021 N/A· v4 5.5 MEDIUM· v3 7.8 HIGH· v2 Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 67Ar8035 Firmware Pm4125 FirmwarePm4250 Firmware+64 moreJun 17, 2026 Apr 7, 2021 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Possible memory corruption in RPM region due to improper XPU configuration in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking |
1Whatsapp 2Whatsapp Whatsapp BusinessJun 17, 2026 Apr 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Busi...Show more |
5Debian FedoraprojectNetapp+2 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreJun 17, 2026 Apr 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called wi...Show more |
An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication. |
3Apple DebianFedoraproject8Debian Linux FedoraIpados+5 moreJun 17, 2026 Apr 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing m...Show more |