← Back
CWE-787

14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anker In
1Roav Dashcam A1 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in co...Show more
An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.Show less
1Anker In
1Roav Dashcam A1 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code executio...Show more
An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.Show less
1F5
1Njs
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.
1F5
1Njs
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.
2Davegamble
Oracle
2Cjson
Timesten In Memory Database
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
2Davegamble
Oracle
2Cjson
Timesten In Memory Database
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
1Kaspersky
1Antivirus Engine
Jun 17, 2026
May 8, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional exe...Show more
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9 Android ID: A-120445479Show less
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interac...Show more
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117607414Show less
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privil...Show more
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117556220Show less
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interac...Show more
In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117554758Show less
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution in the media server with no additional execution...Show more
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-123701862Show less
1Hisilicon
1Hi3516 Firmware
Jun 17, 2026
May 7, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerabili...Show more
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and software, as demonstrated by TENVIS cameras 1.3.3.3, 1.2.7.2, 1.2.1.4, 7.1.20.1.2, and 13.1.1.1.7.2; FDT FD7902 11.3.14.1.3 and 10.3.14.1.3; FOSCAM cameras 3.2.1.1.1_0815 and 3.2.2.2.1_0815; and Dericam cameras V11.3.8.1.12.Show less
1Dlink
10Dcs 5009l Firmware
Dcs 5010l FirmwareDcs 5020l Firmware+7 more
Jun 17, 2026
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long strin...Show more
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).Show less
1Php
1Imagick
Jun 17, 2026
May 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to ou...Show more
In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check that the address will be within the allocated array. This could lead to out of bounds write to memory if the function is called with the data controlled by untrusted party.Show less
1Nih
1Ncbi Toolbox
Nov 21, 2024
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
1Solarwinds
1Dameware Mini Remote Control
Jun 17, 2026
May 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impac...Show more
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.Show less
1Tabslab
1Mailcarrier
Jun 17, 2026
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a related issue to CVE-2019-11395.
1Rockwellautomation
4Armor Compact Guardlogix 5370 Firmware
Compactlogix 5370 L1 FirmwareCompactlogix 5370 L2 Firmware+1 more
Jun 17, 2026
May 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recoveri...Show more
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.Show less