← Back
CWE-787

14,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freebsd
1Freebsd
Jun 17, 2026
Jul 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated...Show more
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arbitrary code execution.Show less
1Realtek
4Rtl8195am Firmware
Rtl8710af FirmwareRtl8711af Firmware+1 more
Jun 17, 2026
Jul 6, 2020
N/A· v4
8.0 HIGH· v3
4.9 MEDIUM· v2
An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EA...Show more
An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Jun 17, 2026
Jul 6, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap ove...Show more
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .Show less
3Apache
DebianFedoraproject
3Debian Linux
FedoraGuacamole
Jun 17, 2026
Jul 2, 2020
N/A· v4
6.7 MEDIUM· v3
6.2 MEDIUM· v2
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs c...Show more
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.Show less
1Leadtools
1Leadtools
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted ANI file can cause a buffer overflow resulting in remote code execution. An attacker can provide a mal...Show more
An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted ANI file can cause a buffer overflow resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Phoenixcontact
2Pc Worx
Pc Worx Express
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient...Show more
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.Show less
1Ntop
1Ndpi
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
1Rockcarry
1Ffjpeg
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.
1Deltaww
1Dopsoft
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause t...Show more
Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.Show less
5Canonical
FedoraprojectLibvncserver Project+2 more
10Fedora
LeapLibvncserver+7 more
Nov 21, 2024
Jun 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, cau...Show more
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.Show less
1Libraw
1Libraw
Jun 17, 2026
Jun 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.
5Apple
CanonicalOracle+2 more
16Communications Cloud Native Core Policy
Communications Messaging ServerCommunications Network Charging And Control+13 more
Jun 17, 2026
Jun 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
1Adobe
1Illustrator
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
1Adobe
1Illustrator
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Illustrator
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Illustrator
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Illustrator
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Illustrator versions 24.0.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
1Adobe
1Bridge
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
1Adobe
1Bridge
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Bridge versions 10.0.1 and earlier version have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
1Adobe
1Bridge
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .