← Back
CWE-787

14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libming
1Libming
Jun 17, 2026
Jan 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call...Show more
An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call to png_write_row in libpng, an out-of-bounds write might occur for some memory layouts.Show less
1Whatsapp
1Whatsapp
Jun 17, 2026
Dec 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293,...Show more
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for Windows Phone prior to v2.18.172.Show less
1Ok File Formats Project
1Ok File Formats
Nov 21, 2024
Dec 31, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.
1Ok File Formats Project
1Ok File Formats
Nov 21, 2024
Dec 31, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.
2Fedoraproject
Msweet
2Fedora
Mini Xml
Nov 21, 2024
Dec 30, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
1Contiki Ng Project
1Contiki Ng
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character.
1Libxsmm Project
1Libxsmm
Nov 21, 2024
Dec 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is s...Show more
There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is seen at different addresses).Show less
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.
1Radare
1Radare2
Nov 21, 2024
Dec 25, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a rela...Show more
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.Show less
1Foxitsoftware
1Quick Pdf Library
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access viol...Show more
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.Show less
1Foxitsoftware
1Quick Pdf Library
Nov 21, 2024
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFro...Show more
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.Show less
1Foxitsoftware
1Quick Pdf Library
Nov 21, 2024
Dec 24, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions res...Show more
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.Show less
1Xmplay
1Xmplay
Nov 21, 2024
Dec 24, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XMPlay 3.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted http:// URL in a .m3u file.
1Wellintech
1Kingscada
Nov 21, 2024
Dec 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially crafted packet to the AlarmServer (AEserver.exe) service listening on TCP port 12401.
1Tinycc
1Tinycc
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in tccasm.c.
1Tinycc
1Tinycc
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c.
1Tinycc
1Tinycc
Nov 21, 2024
Dec 23, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm.c.
1Libraw
1Libraw
Nov 21, 2024
Dec 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.
1Hancom
4Hancom Office 2010
Hancom Office 2014Hancom Office 2018+1 more
Nov 21, 2024
Dec 21, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when...Show more
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.Show less
1Estsoft
1Alzip
Nov 21, 2024
Dec 21, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.