CWE-787
14,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 34D6220 Firmware D6400 FirmwareD7000 Firmware+31 moreJun 17, 2026 Apr 16, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.44, D6400 before 1.0.0.78, D7000v2 before 1.0.0.51, D8500 before 1.0.3.42, DGN2200v4 b...Show more |
1Netgear 18D3600 Firmware D6000 FirmwareD6200 Firmware+15 moreJun 17, 2026 Apr 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6200 before 1.1.00.32, D7000 before 1.0.1.68, DM200 before...Show more |
1Netgear 17D3600 Firmware D6000 FirmwareD6200 Firmware+14 moreJun 17, 2026 Apr 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 befor...Show more |
1Netgear 17D3600 Firmware D6000 FirmwareD6200 Firmware+14 moreJun 17, 2026 Apr 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 befor...Show more |
1Netgear 17D3600 Firmware D6000 FirmwareD6200 Firmware+14 moreJun 17, 2026 Apr 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 befor...Show more |
1Qualcomm 3Qcs605 Firmware Sa6155p FirmwareSm8150 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer over-write when this 0-byte buffer is typecasted to some other structure and hence memory corruption in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SA6155P, SM8150 |
1Qualcomm 21Apq8053 Firmware Apq8096au FirmwareMsm8998 Firmware+18 moreJun 17, 2026 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Out of bound write can occur in radio measurement request if STA receives multiple invalid rrm measurement request from AP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapd...Show more |
1Qualcomm 3Sda845 Firmware Sdm845 FirmwareSm8150 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Kernel was reading the CSL defined reserved field as uint16 instead of uint32 which could lead to memory overflow in Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SM8150 |
1Qualcomm 55Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+52 moreJun 17, 2026 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,...Show more |
1Qualcomm 54Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+51 moreJun 17, 2026 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industria...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSquid+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evalu...Show more |
1Trianglemicroworks 1Dnp3 Source Code Library Jun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-b...Show more |
1Trianglemicroworks 1Scada Data Gateway Jun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied da...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSquid+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is ad...Show more |
1Netgear 17D3600 Firmware D6000 FirmwareD6200 Firmware+14 moreJun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 befor...Show more |
1Microsoft 17Windows 10 1507 Windows 10 1607Windows 10 1709+14 moreJun 17, 2026 Apr 15, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1...Show more |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1709+13 moreJun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems exce...Show more |
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968. |
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. |
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-202...Show more |