← Back
CWE-787

14,753 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,753)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that wit...Show more
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.Show less
6Canonical
DebianMozilla+3 more
15Debian Linux
Enterprise Linux Server AusFirefox+12 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploi...Show more
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
1Google
1Android
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed...Show more
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711Show less
1Ftpgetter
1Ftpgetter
Jun 17, 2026
Jan 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the application. This memory corruption bug can possibly be classified as a NULL pointer derefere...Show more
FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the application. This memory corruption bug can possibly be classified as a NULL pointer dereference.Show less
1Wago
2Pfc100 Firmware
Pfc200 Firmware
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware v...Show more
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.Show less
6Canonical
DebianE2fsprogs Project+3 more
7Debian Linux
E2fsprogsFedora+4 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.7 MEDIUM· v3
4.4 MEDIUM· v2
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An...Show more
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.Show less
13ds
1Catia
Nov 21, 2024
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
1Centurystar Project
1Centurystar
Nov 21, 2024
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
centurystar 7.12 ActiveX Control has a Stack Buffer Overflow
2Libsdl
Redhat
2Enterprise Linux
Simple Directmedia Layer
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-base...Show more
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.Show less
1Fuzezip Project
1Fuzezip
Nov 21, 2024
Jan 7, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
1Google
1Android
Jun 17, 2026
Jan 6, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not...Show more
In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-144168326Show less
1Google
1Android
Jun 17, 2026
Jan 6, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ne...Show more
In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-144167528Show less
1Google
1Android
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...Show more
In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-130246677Show less
1Google
1Android
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...Show more
In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471Show less
2Google
Opensuse
3Backports Sle
ChromeLeap
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Google
Opensuse
3Backports Sle
ChromeLeap
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Google
Opensuse
3Backports Sle
ChromeLeap
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Fontforge
Opensuse
2Fontforge
Leap
Jun 17, 2026
Jan 3, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.