← Back
CWE-787

14,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
6Rv016 Firmware
Rv042 FirmwareRv042g Firmware+3 more
Jun 17, 2026
Jun 18, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.Show less
1Cisco
4Rv110w Firmware
Rv130 FirmwareRv130w Firmware+1 more
Jun 17, 2026
Jun 18, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary c...Show more
Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands. For more information about these vulnerabilities, see the Details section of this advisory.Show less
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Jun 17, 2026
Jun 17, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Jun 17, 2026
Jun 17, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Jun 17, 2026
Jun 17, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
5Canonical
DebianLibvnc Project+2 more
10Debian Linux
LeapLibvncserver+7 more
Jun 17, 2026
Jun 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
1Treck
1Tcp/ip
Jun 17, 2026
Jun 17, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.
1Treck
1Tcp/ip
Jun 17, 2026
Jun 17, 2020
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
1Treck
1Tcp/ip
Jun 17, 2026
Jun 17, 2020
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.
1Treck
1Tcp/ip
Jun 17, 2026
Jun 17, 2020
N/A· v4
10.0 CRITICAL· v3
9.3 HIGH· v2
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
1Ffmpeg
1Ffmpeg
Jun 17, 2026
Jun 16, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
1Schneider Electric
1Modicon M218 Firmware
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sent to the Modicon M218...Show more
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sent to the Modicon M218 Logic Controller.Show less
1Google
1Android
Jun 17, 2026
Jun 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr"...Show more
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430Show less
1Google
1Android
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User...Show more
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-148189280Show less
1Google
1Android
Jun 17, 2026
Jun 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
1Cypress
1Cyw20735 Firmware
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving data is set to 384 bytes, but everything...Show more
On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving data is set to 384 bytes, but everything else is still configured to the usual size of 1092 (which was used for everything in the previous CYW20719 and later CYW20819 evaluation board). To trigger the overflow, an attacker can either send packets over the air or as unprivileged local user. Over the air, the minimal PoC is sending "l2ping -s 600" to the target address prior to any pairing. Locally, the buffer overflow is immediately triggered by opening an ACL or SCO connection to a headset. This occurs because, in WICED Studio 6.2 and 6.4, BT_ACL_HOST_TO_DEVICE_DEFAULT_SIZE and BT_ACL_DEVICE_TO_HOST_DEFAULT_SIZE are set to 384.Show less
1Advantech
1Webaccess
Jun 17, 2026
Jun 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
4Debian
OracleRedislabs+1 more
4Communications Operations Monitor
Debian LinuxLinux Enterprise+1 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and a...Show more
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.Show less
1Intel
1Converged Security Management Engine Firmware
Jun 17, 2026
Jun 15, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Jun 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action st_dev_conne...Show more
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action st_dev_connect, st_dev_disconnect, or st_dev_rconnect with a sufficiently long wan_type key.Show less