CWE-787
14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Fig2dev Project2Fig2dev Ubuntu LinuxNov 21, 2024 Aug 30, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. |
1Adobe 2Acrobat Dc Acrobat Reader DcNov 21, 2024 Aug 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code exe...Show more |
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call ove...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Aug 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server. |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 27, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extract...Show more |
An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly ext...Show more |
3Canonical DebianX.org3Debian Linux Libx11Ubuntu LinuxNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or...Show more |
1Dlink 1Eyeon Baby Monitor Firmware Nov 21, 2024 Aug 24, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge malicious HTTP requests to execute commands; authentication is required b...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-co...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extract...Show more |
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. This vulnerability could theoretically allow a remote authenticated attacker execute arbitrary code...Show more |
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorre...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The v...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker...Show more |
1Belkin 1Wemo Insight Smart Plug Firmware Jun 17, 2026 Aug 21, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet. |
2Nodejs Redhat2Node.js Openshift Container PlatformNov 21, 2024 Aug 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to wri...Show more |
1Yubico 3Piv Manager Piv ToolSmart Card MinidriverNov 21, 2024 Aug 15, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `ykpiv_transfer_data()`: {% highlight c %} if(*out_len + recv_len - 2 > ma...Show more |