← Back
CWE-787

14,775 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,775)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Jul 9, 2026
Jan 8, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 be...Show more
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.Show less
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 be...Show more
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.Show less
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
1Foxitsoftware
2Phantompdf
Reader
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
1Mozilla
1Firefox
Jun 17, 2026
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar...Show more
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable cr...Show more
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
1Wolfssl
1Wolfssl
Jun 17, 2026
Jan 6, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.
1Softmaker
1Softmaker Office
Jun 17, 2026
Jan 6, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscal...Show more
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Jan 5, 2021
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174...Show more
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174 (January 2021).Show less