← Back
CWE-787

14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickLeap+1 more
Jun 17, 2026
Jul 5, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickLeap+1 more
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
2Imagemagick
Opensuse
2Imagemagick
Leap
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.
1Artifex
1Mupdf
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC prop...Show more
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.Show less
2Fedoraproject
Glyphandcog
2Fedora
Xpdfreader
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftot...Show more
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified other impact.Show less
1Xnview
1Xnview
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.
1Xnview
1Xnview
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.
1Xnview
1Xnview
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000001172b0.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000c47ff.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9c2f.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9e7a.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x0000000000002450.
1Acdsee
1Acdsee
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000024ed.
1Faststone
1Image Viewer
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a9601.
1Faststone
1Image Viewer
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a95b1.
1Faststone
1Image Viewer
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x0000000000002d7d.
1Irfanview
1Irfanview
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.
1Irfanview
1Irfanview
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.
1Nlnetlabs
1Name Server Daemon
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.