← Back
CWE-787

14,779 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,779)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
1Omron
4Cx One
Cx PositionCx Protocol+1 more
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
2Google
Microsoft
2Chrome
Edge Chromium
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
1Cesanta
1Mongoose
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
1Cesanta
1Mongoose
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
1Cesanta
1Mongoose
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
1Ezxml Project
1Ezxml
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.
1Ezxml Project
1Ezxml
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.
1Ezxml Project
1Ezxml
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.
2Fedoraproject
Symonics
2Fedora
Libmysofa
Jun 17, 2026
Feb 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.
1Godotengine
1Godot Engine
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can...Show more
A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.Show less
3Cryptography.io
FedoraprojectOracle
3Communications Cloud Native Core Network Function Cloud Native Environment
CryptographyFedora
Jun 17, 2026
Feb 7, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class...Show more
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.Show less
1Gitea
1Gitea
Jun 17, 2026
Feb 5, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.
1Trendmicro
3Apex One
OfficescanWorry Free Business Security
Jun 17, 2026
Feb 4, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate...Show more
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Feb 4, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Pr...Show more
In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11; Patch ID: ALPS05349201.Show less
1Google
1Android
Jun 17, 2026
Feb 4, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....Show more
In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05371580.Show less
1Google
1Android
Jun 17, 2026
Feb 4, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. P...Show more
In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05449962.Show less