← Back
CWE-787

14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
3Esxi
FusionWorkstation
Jun 17, 2026
Apr 1, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out...Show more
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Apr 1, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
2Burrow Wheeler Aligner Project
Canonical
2Burrow Wheeler Aligner
Ubuntu Linux
Jun 17, 2026
Mar 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
1Tianocore
1Edk Ii
Jun 17, 2026
Mar 27, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
4Fedoraproject
OpensuseRedhat+1 more
8Edk Ii
Enterprise LinuxEnterprise Linux Eus+5 more
Jun 17, 2026
Mar 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
1Tianocore
1Edk Ii
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
1Tianocore
1Edk Ii
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
2Opensuse
Tianocore
2Edk Ii
Leap
Nov 21, 2024
Mar 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
1Lcds
1Laquis Scada
Jun 17, 2026
Mar 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process.
1Axtls Project
1Axtls
Jun 17, 2026
Mar 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes value is mismanaged.
1Ghs
1Integrity Rtos
Jun 17, 2026
Mar 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the hea...Show more
An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow.Show less
1Ghs
1Integrity Rtos
Jun 17, 2026
Mar 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. There is a heap-based buffer overflow in the function responsible for printing the shell prompt, when a custom modifi...Show more
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. There is a heap-based buffer overflow in the function responsible for printing the shell prompt, when a custom modifier is used to display information such as a process ID, IP address, or current working directory. Modifier expansion triggers this overflow, causing memory corruption or a crash (and also leaks memory address information).Show less
7Debian
FedoraprojectLibssh2+4 more
13Debian Linux
Enterprise LinuxEnterprise Linux Desktop+10 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SS...Show more
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.Show less
7Debian
FedoraprojectLibssh2+4 more
13Debian Linux
Enterprise LinuxEnterprise Linux Desktop+10 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to e...Show more
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.Show less
5Debian
Libssh2Netapp+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max charac...Show more
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
Jun 17, 2026
Mar 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file.
8Apple
DebianFedoraproject+5 more
14Debian Linux
Enterprise LinuxEnterprise Linux Desktop+11 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execut...Show more
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.Show less
5Canonical
DebianFedoraproject+2 more
8Debian Linux
Enterprise LinuxEnterprise Linux Eus+5 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.Show less
1Insteon
1Hub Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer ov...Show more
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request at 0x9d014e4c the value for the flg key is copied using strcpy to the buffer at $sp+0x270. This buffer is 16 bytes large, sending anything longer will cause a buffer overflow.Show less
1Insteon
1Hub Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands s...Show more
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request At 0x9d014dd8 the value for the id key is copied using strcpy to the buffer at $sp+0x290. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.Show less